
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24018 is a UNIX symbolic link (symlink) following vulnerability in Fortinet FortiClientLinux that allows a local, unprivileged user to escalate their privileges to root. It affects FortiClientLinux versions 7.4.0 through 7.4.4 and 7.2.2 through 7.2.12; FortiClientLinux 8.0 is not affected. The vulnerability was publicly disclosed on March 10, 2026, with Fortinet publishing advisory FG-IR-26-083 on the same date. It carries a CVSS v3.1 base score of 7.8 (High) per Feedly/NVD, and 7.4 (High) per Fortinet's own scoring (Fortinet PSIRT, ZDI).
The vulnerability is classified as CWE-61 (UNIX Symbolic Link Following), mapped to CAPEC-27 (Leveraging Race Conditions via Symbolic Links). A local unprivileged attacker can create or manipulate symbolic links in a location that FortiClientLinux processes with elevated (root) privileges, causing the application to follow the symlink and operate on attacker-controlled files or paths. Exploitation requires low privileges and no user interaction, with low attack complexity, making it straightforward for any local user on an affected system. The vulnerability was discovered externally by Febin Mon Saji of Astra Security, working with Trend Micro's Zero Day Initiative, and reported under responsible disclosure (Fortinet PSIRT, ZDI).
Successful exploitation grants a local unprivileged attacker full root-level access to the affected Linux system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with root access can read or exfiltrate sensitive data, modify or destroy system files, install persistent backdoors, and potentially pivot to other systems on the network. The scope is limited to the local system, but the severity is high given the complete loss of privilege separation (Fortinet PSIRT).
/etc/passwd, /etc/sudoers, or a root-owned script)./etc/passwd or /etc/sudoers coinciding with FortiClientLinux process activity; new files or scripts in root-owned directories created by non-root users./var/log/audit/audit.log) showing symlink creation (SYSCALL records for symlink or symlinkat) by unprivileged users in FortiClientLinux-related paths; auth.log or secure log entries showing unexpected privilege escalation or sudo usage by non-privileged accounts./bin/bash) running as root with a parent process of FortiClientLinux components.Fortinet has released patched versions addressing this vulnerability: users running FortiClientLinux 7.2.2–7.2.12 should upgrade to 7.2.13 or later, and users running 7.4.0–7.4.4 should upgrade to 7.4.5 or later. FortiClientLinux 8.0 is not affected. No configuration-based workaround is provided; upgrading is the recommended and only confirmed remediation. As interim measures, organizations should restrict local user access to affected systems, implement the principle of least privilege, and monitor audit logs for suspicious symlink activity or unexpected privilege escalation (Fortinet PSIRT).
The Belgium Centre for Cybersecurity (CCB) issued a warning advising immediate patching, noting Fortinet patched 22 vulnerabilities across multiple products in this release cycle (CCB Advisory). Singapore's Cyber Security Agency (CSA) also published an alert (AL-2026-024) referencing this and related Fortinet vulnerabilities (CSA Alert). Security researcher Febin Mon Saji published a detailed Medium write-up describing the vulnerability as a logic flaw, and the exploit was subsequently indexed on Sploitus, drawing community attention to the public PoC availability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."