CVE-2026-22573: Path Traversal
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22573?
CVE-2026-22573 is classified as a critical vulnerability due to the potential for unauthorized access to restricted directories.
How do I fix CVE-2026-22573?
To fix CVE-2026-22573, update Fortinet FortiSOAR PaaS and on-premise versions to the latest releases that address this vulnerability.
What products are affected by CVE-2026-22573?
CVE-2026-22573 affects Fortinet FortiSOAR PaaS versions 7.3 to 7.6.3 and all versions of Fortinet FortiSOAR on-premise.
What type of vulnerability is CVE-2026-22573?
CVE-2026-22573 is a path traversal vulnerability that allows attackers to bypass restrictions on directory access.
Can I mitigate CVE-2026-22573 without updating?
Mitigation for CVE-2026-22573 without updating is not recommended as it requires code changes to fully address the vulnerability.