Executive brief
A path traversal vulnerability exists in several Fortinet networking and security products, including FortiOS and FortiPAM. This flaw allows an administrative user with existing read-write permissions to bypass directory restrictions and delete or modify system files. While it requires high-level access to exploit, it could be used by a malicious insider or a compromised administrator account to disrupt operations or damage the integrity of the security appliance.
Technical details
A path traversal vulnerability (CWE-22) exists in the Command Line Interpreter (CLI) of multiple Fortinet products. The root cause is improper limitation of pathnames within specific CLI commands, allowing users to reference files outside of the intended directory. Exploitation requires the attacker to be authenticated with an administrative profile and possess at least read-write permissions. An attacker can leverage this to achieve arbitrary file write or deletion on the underlying filesystem. Fortinet has released updates for affected branches (e.g., FortiOS 7.6.5, 7.4.10) to remediate the issue.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiPAM 1.7.0, 1.6 all versions, 1.5 all versions, 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4.0 through 7.4.11, 7.2 all versions, 7.0 all versions
- Fortinet FortiSwitchManager 7.2.0 through 7.2.7, 7.0.0 through 7.0.6
- Siemens RUGGEDCOM APE1808 (Fortinet NGFW) Versions with Fortinet NGFW < V7.4.10
Timeline
- 2026-03-10: advisory: Initial Siemens advisory published
- 2026-04-14: disclosed: Initial Fortinet publication
- 2026-05-12: other: Siemens advisory updated to include this CVE