CVE-2026-24018

7.8

Fortinet · FortiClientLinux

A symbolic link following vulnerability in FortiClientLinux allows a local, unprivileged user to escalate privileges to root.

Executive summary

A privilege escalation vulnerability in Fortinet FortiClientLinux permits local users to gain root access, posing a severe threat to system integrity and security.

Vulnerability

This is a symbolic link following issue (CWE-61) where the application improperly handles file paths. A local, unprivileged user can leverage this flaw to gain elevated root privileges on the host system.

Business impact

Successful exploitation grants an attacker full administrative control over the affected Linux host. This level of access facilitates the theft of sensitive data, the installation of persistent malware, and the complete compromise of the system, justifying the high CVSS score of 7.8.

Remediation

Immediate Action: Upgrade to FortiClientLinux version 7.4.5, 7.2.13, or the upcoming 8.0.0 release as specified by the vendor.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized attempts to access sensitive root-level directories.

Compensating Controls: Restrict local user access to the system and ensure that non-administrative users operate with the principle of least privilege to limit the potential scope of a privilege escalation attempt.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

Given the ability for an attacker to achieve full root access, this vulnerability presents a significant security risk. Administrators should prioritize updating all instances of FortiClientLinux to the patched versions immediately to prevent potential local privilege escalation attacks.

More Fortinet CVEs

Sources