CVE-2026-16467

7.5

Dolusoft Software · Fortilogger

A missing authorization vulnerability in Dolusoft Fortilogger allows unauthenticated attackers to access restricted system functions.

Executive summary

A missing authorization flaw in Dolusoft Fortilogger enables unauthenticated remote attackers to bypass access controls and interact with sensitive application features.

Vulnerability

The software contains a missing authorization flaw that permits unauthenticated remote users to access functionality that should be restricted by access control lists.

Business impact

The inability to enforce proper authorization allows an attacker to interact with the application as if they were a privileged user. With a CVSS score of 7.5, this vulnerability represents a high risk to the overall security posture of the affected environment, potentially leading to the compromise of log data or administrative configuration settings.

Remediation

Immediate Action: Update Fortilogger to version 6.1.5.9 or later to remediate the authorization check failure.

Proactive Monitoring: Closely monitor server logs for unauthorized access patterns or attempts to reach restricted administrative interfaces.

Compensating Controls: Utilize network-level access controls or a WAF to restrict public access to the Fortilogger management interface while the update is pending.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity and the ease of access for remote attackers, immediate remediation is required. Organizations should apply the vendor-provided security update to version 6.1.5.9 to ensure that proper authorization checks are enforced across all application functions.

More Dolusoft Software CVEs