Description
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Fortilogger: before 6.1.5.9.
Published: 2026-08-17
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Dolusoft Software Technologies Fortilogger allows an authenticated user to access functionality that is not properly constrained by access control lists. This results in unauthorized data manipulation or exposure, and it is aligned with CWE-862 – Missing Authorization.

Affected Systems

The vulnerability affects all versions of Fortilogger installed before 6.1.5.9. The affected product is Fortilogger from Dolusoft Software Technologies.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, reflecting moderate to high severity, and its EPSS score is not available, indicating uncertain exploitation prevalence in the current environment. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an authenticated user abusing privileged interfaces that lack proper access checks, implying that without immediate remediation, attackers could gain unauthorized control over protected operations.

Generated by OpenCVE AI on August 17, 2026 at 14:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fortilogger to version 6.1.5.9 or later, where the missing authorization check has been fixed.
  • Review and enforce access control lists to confirm that all restricted functionalities are properly protected and that no privilege escalation paths remain.
  • Perform a penetration test or audit of authenticated access controls to verify that the vulnerability has been fully remediated.

Generated by OpenCVE AI on August 17, 2026 at 14:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
Title Broken Access Control in Dolusoft Software's Fortilogger
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-17T14:11:27.579Z

Reserved: 2026-07-21T13:27:08.081Z

Link: CVE-2026-16467

cve-icon Vulnrichment

Updated: 2026-08-17T14:11:23.776Z

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:50.963

Modified: 2026-08-17T14:20:20.040

Link: CVE-2026-16467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T14:45:04Z

Weaknesses