CVE-2026-59839
FortiOS vulnerability analysis and mitigation

Overview

CVE-2026-59839 is a path traversal vulnerability (CWE-22) in Fortinet FortiOS, FortiPAM, and FortiProxy that may allow a privileged authenticated attacker with physical access to delete the file system via crafted CLI commands. It was published on July 14, 2026, and reported by the UK's National Cyber Security Centre (NCSC) under responsible disclosure. Affected products include FortiOS 6.4 through 7.6.6, FortiPAM 1.0 through 1.8.0, and FortiProxy 7.0 through 7.6.5. The vulnerability carries a CVSSv3 score of 5.0 (Medium) (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and resides in the CLI component of the affected Fortinet products. An attacker can craft specific CLI commands that traverse outside the intended restricted directory, potentially reaching and deleting root file system contents. Exploitation requires the attacker to be a privileged authenticated user with physical access to the device, making the attack vector physical (AV:P) with high privilege requirements (PR:H). No public proof-of-concept code has been identified (FortiGuard Advisory).

Impact

Successful exploitation allows a privileged attacker with physical device access to delete arbitrary files on the root file system, resulting in high integrity and availability impacts with no confidentiality impact. This could lead to complete service disruption or destruction of the device's operating environment, potentially rendering network security appliances inoperable. Given the physical access requirement, the scope of impact is limited to the directly targeted device without a clear path to remote lateral movement (FortiGuard Advisory).

Exploitation steps

  1. Physical Access: Gain physical access to a vulnerable Fortinet device (FortiOS, FortiPAM, or FortiProxy) running an affected firmware version.
  2. Authentication: Authenticate to the device CLI using high-privileged credentials (e.g., administrator account).
  3. Craft Malicious CLI Command: Construct a CLI command that includes path traversal sequences (e.g., ../ or encoded equivalents) to escape the restricted directory context.
  4. Execute Command: Submit the crafted CLI command to traverse outside the intended directory boundary and target files on the root file system.
  5. File System Deletion: The traversal bypasses pathname restrictions, allowing deletion of critical root file system files, potentially causing device failure or service disruption (FortiGuard Advisory).

Indicators of compromise

  • Logs: Unusual or unexpected CLI command entries in device audit logs containing path traversal patterns (e.g., ../, %2e%2e%2f) in file path arguments.
  • File System: Missing or deleted system files in root directories not attributable to legitimate administrative actions; unexpected changes to file system integrity.
  • Process/CLI: CLI session activity from privileged accounts at unusual times or from unexpected physical console ports.
  • System Behavior: Unexpected device instability, boot failures, or service outages following CLI activity, which may indicate root file system corruption or deletion (FortiGuard Advisory).

Mitigation and workarounds

Fortinet has released patched versions and recommends upgrading immediately: FortiOS to 7.6.7 or above (7.4 branch: 7.4.10+); FortiPAM to 1.8.1 or above (1.7 branch: 1.7.3+); FortiProxy to 7.6.6 or above (7.4 branch: 7.4.14+). Users on FortiOS 7.2, 7.0, or 6.4, FortiPAM versions below 1.7, and FortiProxy 7.2 or 7.0 should migrate to a fixed release branch. A virtual patch named "FG-VD-60139.0day" is available in FMWP database update 26.021 for environments that cannot immediately upgrade. Restricting physical access to affected devices is a critical compensating control given the physical attack vector requirement (FortiGuard Advisory).

Community reactions

The vulnerability was part of a broader Fortinet patch release covering seven security flaws across FortiOS, FortiProxy, FortiPAM, and FortiSandbox, which received coverage from security news outlets including CyberSecurityNews, GBHackers, and CyberPress. Community and media attention was moderate, consistent with a medium-severity, physically-exploitable vulnerability. No notable individual researcher commentary or significant social media debate has been identified beyond standard vulnerability reporting (CyberSecurityNews, GBHackers).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59837MEDIUM6.6
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-23573MEDIUM6.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2025-62826MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management