CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59839

mediumCVSS 5.5covered by 4 sourcesfirst seen 2026-07-14
CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
A privileged authenticated attacker may delete the file system via crafted CLI commands.
Who is affected
Privileged authenticated users of FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager.
Urgency
Remediation is critical to prevent potential system destruction.
Action
Restrict CLI command access to authorized personnel only.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-59839

Get an email if CVE-2026-59839 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-59839

CVE.org record

Embed the live status

CVE-2026-59839 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59839 status](https://www.csirts.com/badge/CVE-2026-59839)](https://www.csirts.com/cve/CVE-2026-59839)