CVE-2022-26117

8.8
HIGHCVSS v3.1 Base Score
0.93%
LOW RiskEPSS (58th percentile)

An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI.

Published: 7/18/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.93%LOW Exploitation Risk
58th percentile

This vulnerability has a 0.93% probability of being exploited in the next 30 days, ranking higher than 58% of all scored CVEs.

CWE Classification

Advertisement