Junglewise Threat Intelligence

CVE-2026-59840: Fortinet FortiOS and FortiProxy buffer over-read in authd and wad daemons

CVE-2026-59840 · Severity: medium · CVSS 4.3 · Published 2026-07-14

Technologies: Fortinet FortiOS, Fortinet Fortisase, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

Fortinet FortiOS and FortiProxy, which are used to manage network security and web traffic, contain a security flaw. An authenticated user could potentially view sensitive information stored in the device's memory by sending a specially crafted request. This could lead to the unauthorized disclosure of internal system data, though it does not allow for full system takeover.

Technical details

A buffer over-read vulnerability (CWE-126) exists in the authd and wad daemons of Fortinet FortiOS, FortiProxy, and FortiSASE. The flaw is triggered when the system processes a specially crafted request, causing it to return a portion of device memory within a redirect response. An attacker must be authenticated (PR:L) to exploit this vulnerability over the network. Successful exploitation results in information disclosure, potentially revealing sensitive data residing in the memory space of the affected processes. Patches are available in FortiOS 7.6.4, 7.4.9, and FortiProxy 7.6.6 and 7.4.14.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.5, 7.4.0 through 7.4.13, 7.2 all versions
  • Fortinet FortiSASE All versions

Timeline

  • 2026-07-14: advisory: Initial publication by Fortinet

References

Related threats