High severity7.8NVD Advisory· Published Mar 10, 2026· Updated Jun 17, 2026
CVE-2026-24018
CVE-2026-24018
Description
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*range: >=7.2.2,<7.2.13
- cpe:2.3:a:fortinet:forticlientlinux:7.4.4:*:*:*:*:*:*:*range: 7.4.0
- (no CPE)range: 7.4.0-7.4.4, 7.2.2-7.2.12
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-26-083nvdVendor Advisory
News mentions
1- ZDI-26-186: Fortinet FortiClient Link Following Local Privilege Escalation VulnerabilityZero Day Initiative · Mar 10, 2026