Improper limitation of a pathname to a restricted directory
Fortinet warns of a CVSS 9.8 path traversal that lets unauthenticated attackers write arbitrary files, with in-the-wild exploitation reported.
Fortinet PSIRT advisory FG-IR-26-175 describes a path traversal (CWE-22) combined with improper NULL-byte handling (CWE-158), scored CVSS 9.8. An unauthenticated attacker can write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet says exploitation has been reported in the wild and urges customers to apply the published workaround. The notice was revised on 2026-10-01, and the text does not name a CVE.
- CVSS 9.8 path traversal plus a NULL-byte flaw (CWE-22, CWE-158).
- Unauthenticated HTTP or HTTPS requests can write arbitrary files.
- Fortinet reports exploitation in the wild and urges the workaround.
- Advisory ID FG-IR-26-175; no CVE is named in the text.
CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-01 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.