CVE-2026-24018
FortiClient vulnerability analysis and mitigation

Overview

CVE-2026-24018 is a UNIX symbolic link (symlink) following vulnerability in Fortinet FortiClientLinux that allows a local, unprivileged user to escalate their privileges to root. It affects FortiClientLinux versions 7.4.0 through 7.4.4 and 7.2.2 through 7.2.12; FortiClientLinux 8.0 is not affected. The vulnerability was publicly disclosed on March 10, 2026, with Fortinet publishing advisory FG-IR-26-083 on the same date. It carries a CVSS v3.1 base score of 7.8 (High) per Feedly/NVD, and 7.4 (High) per Fortinet's own scoring (Fortinet PSIRT, ZDI).

Technical details

The vulnerability is classified as CWE-61 (UNIX Symbolic Link Following), mapped to CAPEC-27 (Leveraging Race Conditions via Symbolic Links). A local unprivileged attacker can create or manipulate symbolic links in a location that FortiClientLinux processes with elevated (root) privileges, causing the application to follow the symlink and operate on attacker-controlled files or paths. Exploitation requires low privileges and no user interaction, with low attack complexity, making it straightforward for any local user on an affected system. The vulnerability was discovered externally by Febin Mon Saji of Astra Security, working with Trend Micro's Zero Day Initiative, and reported under responsible disclosure (Fortinet PSIRT, ZDI).

Impact

Successful exploitation grants a local unprivileged attacker full root-level access to the affected Linux system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with root access can read or exfiltrate sensitive data, modify or destroy system files, install persistent backdoors, and potentially pivot to other systems on the network. The scope is limited to the local system, but the severity is high given the complete loss of privilege separation (Fortinet PSIRT).

Exploitation steps

  1. Reconnaissance: Identify a target Linux system running FortiClientLinux versions 7.2.2–7.2.12 or 7.4.0–7.4.4 with a local unprivileged user account.
  2. Identify vulnerable path: Locate a file path or directory that FortiClientLinux accesses or writes to with root privileges during normal operation (e.g., during updates, log writes, or configuration operations).
  3. Create malicious symlink: As the unprivileged user, replace or create a symbolic link at the target path pointing to a sensitive root-owned file or directory (e.g., /etc/passwd, /etc/sudoers, or a root-owned script).
  4. Trigger privileged operation: Cause FortiClientLinux to perform the privileged file operation (e.g., by initiating a scan, update, or configuration change), which follows the symlink and operates on the attacker-controlled target path with root privileges.
  5. Achieve root access: Depending on the target path, the attacker can overwrite critical system files, inject commands into root-executed scripts, or read sensitive credentials — ultimately achieving root-level code execution or persistent privilege escalation (ZDI, Medium Write-up).

Indicators of compromise

  • File System: Unexpected symbolic links in directories accessed by FortiClientLinux (e.g., temp directories, log paths, or configuration directories); modification timestamps on sensitive files like /etc/passwd or /etc/sudoers coinciding with FortiClientLinux process activity; new files or scripts in root-owned directories created by non-root users.
  • Logs: System audit logs (/var/log/audit/audit.log) showing symlink creation (SYSCALL records for symlink or symlinkat) by unprivileged users in FortiClientLinux-related paths; auth.log or secure log entries showing unexpected privilege escalation or sudo usage by non-privileged accounts.
  • Process: Unexpected root-owned processes spawned from or related to FortiClientLinux; shell processes (e.g., /bin/bash) running as root with a parent process of FortiClientLinux components.
  • Network: Outbound connections from the compromised host to unknown external IPs following local privilege escalation, potentially indicating post-exploitation activity.

Mitigation and workarounds

Fortinet has released patched versions addressing this vulnerability: users running FortiClientLinux 7.2.2–7.2.12 should upgrade to 7.2.13 or later, and users running 7.4.0–7.4.4 should upgrade to 7.4.5 or later. FortiClientLinux 8.0 is not affected. No configuration-based workaround is provided; upgrading is the recommended and only confirmed remediation. As interim measures, organizations should restrict local user access to affected systems, implement the principle of least privilege, and monitor audit logs for suspicious symlink activity or unexpected privilege escalation (Fortinet PSIRT).

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued a warning advising immediate patching, noting Fortinet patched 22 vulnerabilities across multiple products in this release cycle (CCB Advisory). Singapore's Cyber Security Agency (CSA) also published an alert (AL-2026-024) referencing this and related Fortinet vulnerabilities (CSA Alert). Security researcher Febin Mon Saji published a detailed Medium write-up describing the vulnerability as a logic flaw, and the exploit was subsequently indexed on Sploitus, drawing community attention to the public PoC availability.

Additional resources


SourceThis report was generated using AI

Related FortiClient vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24018HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMar 10, 2026
CVE-2025-47761HIGH7.8
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025
CVE-2025-62676HIGH7.1
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesFeb 10, 2026
CVE-2026-44278MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesMay 12, 2026
CVE-2025-54660MEDIUM5.5
  • FortiClient logoFortiClient
  • cpe:2.3:a:fortinet:forticlient
NoYesNov 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management