SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-59839

MEDIUM · CVSS 5.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Fortinet's FortiOS, FortiPAM, and FortiProxy products are vulnerable to a path traversal flaw that could enable attackers to execute unauthorized code or commands. This vulnerability affects multiple versions across these products, specifically FortiOS versions 7.6.0 to 7.6.6, 7.4.0 to 7.4.9, and earlier versions, as well as various FortiPAM and FortiProxy releases. Organizations using these affected versions should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-59839
Severity
MEDIUM
CVSS
5.5
EPSS
0.22%
Fortinet FortiOS

Original NVD Description

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Related CVEs

Other vulnerabilities affecting the same vendor(s)