Junglewise Threat Intelligence

CVE-2026-59839: Fortinet FortiOS and FortiProxy path traversal in CLI

CVE-2026-59839 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Fortinet Fortipam, Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A security vulnerability exists in several Fortinet networking and security products, including FortiOS and FortiProxy, which are used to manage corporate networks and secure web traffic. A highly privileged user with physical access to the device could use specific commands to delete critical system files. This could lead to a complete failure of the device, causing significant network downtime and requiring manual restoration of the hardware.

Technical details

A path traversal vulnerability (CWE-22) exists in the Command Line Interface (CLI) of multiple Fortinet products. The flaw is rooted in improper limitation of pathnames to restricted directories within specific CLI commands. An attacker must have physical access to the device and possess high-level administrative privileges (PR:H) to exploit this. Successful exploitation allows the attacker to traverse the file system and delete critical files, including the root file system, leading to a denial-of-service condition or unauthorized command execution. Patches are available for several versions, including FortiOS 7.4.10 and FortiProxy 7.6.6.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.6, 7.4.0 through 7.4.9, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiPAM 1.8.0, 1.7.0 through 1.7.2, 1.6 all versions, 1.5 all versions, 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.5, 7.4 through 7.4.13, 7.2 all versions, 7.0 all versions
  • Fortinet FortiSwitch Manager All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Fortinet PSIRT
  • 2026-07-14: advisory: NVD entry created

References

Related threats