CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Path traversal in CLI command allows deletion of root file system

unknownCVE-2026-59839
CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
A privileged authenticated attacker may delete the file system via crafted CLI commands.
Who is affected
Privileged authenticated users of FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager.
Urgency
Remediation is critical to prevent potential system destruction.
Action
Restrict CLI command access to authorized personnel only.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FortiOS, FortiPAM, FortiProxy, FortiSwitch Manager

Get an email when a new FortiOS, FortiPAM, FortiProxy, FortiSwitch Manager advisory drops — max one per day, one-click unsubscribe.

Details

Source
Fortinet FortiGuard PSIRT (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-151

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59839coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Path traversal in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Fortinet FortiGuard PSIRT