CVE-2026-59839

MEDIUM

Fortinet FortiProxy - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Title source: rule
STIX 2.1

Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (22)
Fortinet/FortiOS 6.4.0 - 6.4.16
fortinet/fortios 6.4.0 - 7.4.10
Fortinet/FortiOS 7.0.0 - 7.0.19
Fortinet/FortiOS 7.2.0 - 7.2.13
Fortinet/FortiOS 7.4.0 - 7.4.9
Fortinet/FortiOS 7.6.0 - 7.6.6
fortinet/fortipam 1.8.0
Fortinet/FortiPAM 1.0.0 - 1.0.3
fortinet/fortipam 1.0.0 - 1.7.3
Fortinet/FortiPAM 1.1.0 - 1.1.2
... and 12 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026