CVE-2026-59837: Stack Buffer Overflow in Log Report
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
Other sources
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.2 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.0 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.8.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.9.0 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.14 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59837?
The severity of CVE-2026-59837 is medium with a base score of 6.6.
How do I fix CVE-2026-59837?
To fix CVE-2026-59837, update your Fortinet FortiOS, FortiProxy, or FortiPAM to the latest patch provided by the vendor.
Who is affected by CVE-2026-59837?
CVE-2026-59837 affects users of Fortinet FortiOS, FortiProxy, and FortiPAM that allow privileged authenticated access.
What type of vulnerability is CVE-2026-59837?
CVE-2026-59837 is a stack-based buffer overflow vulnerability that can be exploited through crafted HTTP requests.
What can an attacker achieve by exploiting CVE-2026-59837?
An attacker who exploits CVE-2026-59837 can execute arbitrary code or commands on the affected systems.