CVE-2026-59839
Reported by fortinet · Published July 14, 2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiProxy | 7.6.0, 7.4.0, 7.2.0 |
| Fortinet | FortiOS | 7.6.0, 7.4.0, 7.2.0 |
| Fortinet | FortiPAM | 1.8.0, 1.7.0, 1.6.0 |
| Fortinet | FortiPAM | 1.0.0, 1.8.0, 1.7.0 |
| Fortinet | FortiOS | 7.6.0, 7.4.0, 7.2.0 |
| Fortinet | FortiProxy | 7.6.0, 7.4.0, 7.2.0 |
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 15, 2026 CVE Updated
- Jul 15, 2026 Security Advisory