CVE-2026-24018

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
13.6th percentile
Discovered by
Not disclosed
Published
Mar 10, 2026
Assigned by fortinet

Description

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

Weakness: CWE-61

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiClientLinux

Vendor remediation

Upgrade to upcoming FortiClientLinux version 8.0.0 or above Upgrade to FortiClientLinux version 7.4.5 or above Upgrade to FortiClientLinux version 7.2.13 or above