CVE-2026-71407

medium Fortinet
CVSS v3 Base Score
5.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
Low
Published: August 12, 2026 (25 days ago)
Last Modified: August 13, 2026
Vendor: Fortinet
Source: MITRE

Description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

CWE

CWE-121

Affected Products

Fortinet FortiOSFortinet FortiPAMFortinet FortiProxy

References