Medium severity5.5NVD Advisory· Published Jul 14, 2026· Updated Aug 11, 2026
CVE-2026-59839
CVE-2026-59839
Description
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=7.0.0,<7.4.14
- (no CPE)range: 7.6.0-7.6.5, 7.4.0-7.4.13, 7.2.x, 7.0.x
Patches
Vulnerability mechanics
References
2News mentions
1- Siemens RUGGEDCOM APE1808CISA ICS Advisories