
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59839 is a path traversal vulnerability (CWE-22) in Fortinet FortiOS, FortiPAM, and FortiProxy that may allow a privileged authenticated attacker with physical access to delete the file system via crafted CLI commands. It was published on July 14, 2026, and reported by the UK's National Cyber Security Centre (NCSC) under responsible disclosure. Affected products include FortiOS 6.4 through 7.6.6, FortiPAM 1.0 through 1.8.0, and FortiProxy 7.0 through 7.6.5. The vulnerability carries a CVSSv3 score of 5.0 (Medium) (FortiGuard Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and resides in the CLI component of the affected Fortinet products. An attacker can craft specific CLI commands that traverse outside the intended restricted directory, potentially reaching and deleting root file system contents. Exploitation requires the attacker to be a privileged authenticated user with physical access to the device, making the attack vector physical (AV:P) with high privilege requirements (PR:H). No public proof-of-concept code has been identified (FortiGuard Advisory).
Successful exploitation allows a privileged attacker with physical device access to delete arbitrary files on the root file system, resulting in high integrity and availability impacts with no confidentiality impact. This could lead to complete service disruption or destruction of the device's operating environment, potentially rendering network security appliances inoperable. Given the physical access requirement, the scope of impact is limited to the directly targeted device without a clear path to remote lateral movement (FortiGuard Advisory).
../ or encoded equivalents) to escape the restricted directory context.../, %2e%2e%2f) in file path arguments.Fortinet has released patched versions and recommends upgrading immediately: FortiOS to 7.6.7 or above (7.4 branch: 7.4.10+); FortiPAM to 1.8.1 or above (1.7 branch: 1.7.3+); FortiProxy to 7.6.6 or above (7.4 branch: 7.4.14+). Users on FortiOS 7.2, 7.0, or 6.4, FortiPAM versions below 1.7, and FortiProxy 7.2 or 7.0 should migrate to a fixed release branch. A virtual patch named "FG-VD-60139.0day" is available in FMWP database update 26.021 for environments that cannot immediately upgrade. Restricting physical access to affected devices is a critical compensating control given the physical attack vector requirement (FortiGuard Advisory).
The vulnerability was part of a broader Fortinet patch release covering seven security flaws across FortiOS, FortiProxy, FortiPAM, and FortiSandbox, which received coverage from security news outlets including CyberSecurityNews, GBHackers, and CyberPress. Community and media attention was moderate, consistent with a medium-severity, physically-exploitable vulnerability. No notable individual researcher commentary or significant social media debate has been identified beyond standard vulnerability reporting (CyberSecurityNews, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."