CVE-2026-59837

MEDIUM

Fortinet FortiPAM - Stack-based Buffer Overflow

Title source: rule
STIX 2.1

Description

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

References (1)

Core 1

Scores

CVSS v3 6.6
EPSS 0.0058
EPSS Percentile 44.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (19)
Fortinet/FortiOS 6.4.0 - 6.4.16
Fortinet/FortiOS 7.0.0 - 7.0.19
Fortinet/FortiOS 7.2.0 - 7.2.13
fortinet/fortios 7.2.0 - 7.4.2
Fortinet/FortiOS 7.4.0 - 7.4.1
Fortinet/FortiPAM 1.0.0 - 1.0.3
fortinet/fortipam 1.0.0 - 1.8.3
Fortinet/FortiPAM 1.1.0 - 1.1.2
Fortinet/FortiPAM 1.2.0
Fortinet/FortiPAM 1.3.0 - 1.3.1
... and 9 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026