CVE-2026-59840: Buffer overread in authd and wad daemon
A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Other sources
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.14 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.6 - Compensating control
No action required for FortiSASE because Fortinet remediated the issue in FortiSASE version 25.4.b.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59840?
The severity of CVE-2026-59840 is medium with a score of 4.3.
What systems are affected by CVE-2026-59840?
CVE-2026-59840 affects Fortinet FortiOS, FortiProxy, and FortiSASE.
How can I fix CVE-2026-59840?
To fix CVE-2026-59840, update Fortinet FortiOS and FortiProxy to the latest patched version.
What type of vulnerability is CVE-2026-59840?
CVE-2026-59840 is classified as a buffer over-read vulnerability.
Who can exploit CVE-2026-59840?
CVE-2026-59840 can be exploited by an authenticated remote attacker.