Home

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions.

PUBLISHED Reserved 2026-01-07 | Published 2026-04-14 | Updated 2026-04-14 | Assigner fortinet




MEDIUM: 6.2CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C

Problem types

Information disclosure

Product status

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-26-116

cve.org (CVE-2026-22573)

nvd.nist.gov (CVE-2026-22573)

Download JSON