CVE-2026-24018

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
13.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

Weakness: CWE-61

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientLinux

Credit

Fortinet is pleased to thank Febin Mon Saji from Astra Security working with Trend Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to upcoming FortiClientLinux version 8.0.0 or above Upgrade to FortiClientLinux version 7.4.5 or above Upgrade to FortiClientLinux version 7.2.13 or above

Something wrong here?