CVE-2026-24018: High severity Fortinet FortiClientLinux vulnerability
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24018?
CVE-2026-24018 is considered a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-24018?
To fix CVE-2026-24018, you should upgrade Fortinet FortiClientLinux to version 7.4.5 or later for 7.4.x and 7.2.13 or later for 7.2.x.
Who is affected by CVE-2026-24018?
CVE-2026-24018 affects users of Fortinet FortiClientLinux versions 7.4.0 to 7.4.4 and 7.2.2 to 7.2.12.
Can CVE-2026-24018 be exploited remotely?
No, CVE-2026-24018 requires local access to exploit, as it involves symbolic link following.
What is the impact of CVE-2026-24018?
The impact of CVE-2026-24018 allows local unprivileged users to escalate their privileges to root on affected systems.