Path traversal in CLI command allows deletion of root file system

MonitorCVSS 5FG-IR-26-151Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorPhysical
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

Path traversal vulnerability in CLI command input validation allows authenticated high-privilege users to bypass file access restrictions and delete arbitrary files on the device using directory traversal sequences. Exploitation could delete critical system files and render the device inoperable. The vulnerability affects multiple FortiOS, FortiPAM, and FortiProxy product lines across various versions. Affected products include FortiOS 7.0–7.6, FortiPAM 1.6–1.8, and FortiProxy 7.0–7.6. Several product versions have no patch available and require migration to fixed releases.

What this means
What could happen
An authenticated administrative user could exploit a path traversal flaw in CLI commands to delete arbitrary files on the device, including critical system files that would render the device unable to operate or recover.
Who's at risk
Fortinet device administrators and engineers managing FortiOS firewalls, FortiPAM privileged access management systems, or FortiProxy appliances should prioritize this vulnerability. Any organization relying on these devices for network security or administrative access control should verify their device versions against the affected ranges.
How it could be exploited
An attacker with high-privilege administrative credentials uses a CLI command with a crafted path containing directory traversal sequences (e.g., "../") to bypass file access restrictions and delete files outside the intended directory. By targeting system-critical files, the attacker could disable the device's core functionality.
Prerequisites
  • High-privilege (administrator) credentials for CLI access
  • Direct or proxied access to the device's command-line interface (SSH, console, or remote management port)
  • Knowledge of critical file system paths on the target device
No authentication bypass required (requires high-privilege credentials)High-privilege access required (mitigating factor)EPSS score extremely low (0.2%)No active exploitation observedModerate severity with high impact on device availability
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
FortiOS7.4.0 - 7.4.97.4.10+
FortiOS7.2 all versionsMigrate to fixed release
FortiOS7.0 all versionsMigrate to fixed release
FortiOS6.4 all versionsMigrate to fixed release
FortiPAM1.8.01.8.1+
FortiPAM1.6 all versions and 6 moreMigrate to fixed release
FortiProxy7.6.0 - 7.6.57.6.6+
FortiProxy7.4 - 7.4.137.4.14+
Remediation & Mitigation
0/5
Do now
0/1
HARDENINGRestrict CLI access to only trusted administrative users and workstations; disable remote CLI access (SSH) if not operationally required
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS to version 7.4.10 or later (7.6.x has no fix; plan migration to next stable release)
FortiPAM
HOTFIXUpdate FortiPAM to version 1.8.1 or later (1.7.x has no fix; plan migration)
FortiProxy
HOTFIXUpdate FortiProxy to version 7.6.6 or 7.4.14 or later
Long-term hardening
0/1
HARDENINGMonitor CLI logs for use of directory traversal sequences (../ or similar) in commands to detect suspicious activity
API: /api/v1/advisories/29156294-909d-4ee6-b18f-9b6ba0c71660

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Path traversal in CLI command allows deletion of root file system | CVSS 5 - OTPulse