CVE-2026-16467
7.5Dolusoft Software · Fortilogger
A missing authorization vulnerability in Dolusoft Fortilogger allows unauthenticated attackers to access restricted system functions.
Executive summary
A missing authorization flaw in Dolusoft Fortilogger enables unauthenticated remote attackers to bypass access controls and interact with sensitive application features.
Vulnerability
The software contains a missing authorization flaw that permits unauthenticated remote users to access functionality that should be restricted by access control lists.
Business impact
The inability to enforce proper authorization allows an attacker to interact with the application as if they were a privileged user. With a CVSS score of 7.5, this vulnerability represents a high risk to the overall security posture of the affected environment, potentially leading to the compromise of log data or administrative configuration settings.
Remediation
Immediate Action: Update Fortilogger to version 6.1.5.9 or later to remediate the authorization check failure.
Proactive Monitoring: Closely monitor server logs for unauthorized access patterns or attempts to reach restricted administrative interfaces.
Compensating Controls: Utilize network-level access controls or a WAF to restrict public access to the Fortilogger management interface while the update is pending.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity and the ease of access for remote attackers, immediate remediation is required. Organizations should apply the vendor-provided security update to version 6.1.5.9 to ensure that proper authorization checks are enforced across all application functions.