Impact
A missing authorization check in Dolusoft Software Technologies Fortilogger allows an authenticated user to access functionality that is not properly constrained by access control lists. This results in unauthorized data manipulation or exposure, and it is aligned with CWE-862 – Missing Authorization.
Affected Systems
The vulnerability affects all versions of Fortilogger installed before 6.1.5.9. The affected product is Fortilogger from Dolusoft Software Technologies.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, reflecting moderate to high severity, and its EPSS score is not available, indicating uncertain exploitation prevalence in the current environment. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an authenticated user abusing privileged interfaces that lack proper access checks, implying that without immediate remediation, attackers could gain unauthorized control over protected operations.
OpenCVE Enrichment