FG-IR-26-143: Restricted CLI escape using Lua
Published Jun 9, 2026
·Updated
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands.
Affected Software
6 affected componentsFixes available
Fortinet FortiOS>=7.6.0<=7.6.2
Fortinet FortiOS>=7.4.0<=7.4.7
Fortinet FortiOS>=7.2.0<=7.2.10
Fortinet FortiProxy>=7.6.0<=7.6.3
Fortinet FortiProxy>=7.4.0<=7.4.10
Fortinet FortiProxy>=7.2.0<=7.2.14
Event History
Jun 9, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-143?
The severity of FG-IR-26-143 is medium, rated at 6.
2
How do I fix FG-IR-26-143?
To fix FG-IR-26-143, update to the latest version of FortiOS or FortiProxy that mitigates this vulnerability.
3
What does FG-IR-26-143 affect?
FG-IR-26-143 affects Fortinet FortiOS and Fortinet FortiProxy software.
4
What type of access does FG-IR-26-143 involve?
FG-IR-26-143 involves restricted CLI escape using Lua scripts via crafted commands.
5
What could an attacker potentially do with FG-IR-26-143?
An attacker with authenticated access could execute unauthorized Lua scripts, compromising the system.