IM
IronMonkey Threat Research

CVE-2026-59839 MEDIUM

Published: 2026-07-14 | Last Modified: 2026-08-11 | Status: Modified

Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Attack VectorPHYSICAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 0.3

Impact Score: 5.2

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22

Affected Products

Vendor Product Version Update Type
fortinet fortiproxy * <built-in method update of dict object at 0x72f059924240> Application
fortinet fortiproxy * <built-in method update of dict object at 0x72f059924500> Application
fortinet fortios * <built-in method update of dict object at 0x72effefaed00> Operating System
fortinet fortios * <built-in method update of dict object at 0x72f059925540> Operating System
fortinet fortipam * <built-in method update of dict object at 0x72f059925180> Operating System
fortinet fortipam 1.8.0 <built-in method update of dict object at 0x72f059924c00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortipam:1.8.0:*:*:*:*:*:*:*
Notification
Message here