Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via

Severity (CVSS)

Base score5
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
Provided byCNA

Weaknesses

  • CWE-22 — Execute unauthorized code or commands

Affected products

VendorProductVersions
FortinetFortiProxy7.6.0 to <=7.6.5; 7.4.0 to <=7.4.13; 7.2.0 to <=7.2.16; 7.0.0 to <=7.0.23
FortinetFortiOS7.6.0 to <=7.6.6; 7.4.0 to <=7.4.9; 7.2.0 to <=7.2.13; 7.0.0 to <=7.0.19; 6.4.0 to <=6.4.16
FortinetFortiPAM1.8.0; 1.7.0 to <=1.7.2; 1.6.0 to <=1.6.2; 1.5.0 to <=1.5.1; 1.4.0 to <=1.4.3; 1.3.0 to <=1.3.1; 1.2.0; 1.1.0 to <=1.1.2; 1.0.0 to <=1.0.3

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.