CVE-2026-71407

Summary

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiOS7.6.1 <= 7.6.6affected
FortinetFortiPAM1.8.0 <= 1.8.4affected
FortinetFortiPAM1.7.0 <= 1.7.2affected
FortinetFortiPAM1.6.0 <= 1.6.2affected
FortinetFortiPAM1.5.0 <= 1.5.1affected
FortinetFortiPAM1.4.0 <= 1.4.3affected
FortinetFortiPAM1.3.0 <= 1.3.1affected
FortinetFortiPAM1.2.0affected
FortinetFortiPAM1.1.0 <= 1.1.2affected
FortinetFortiPAM1.0.0 <= 1.0.3affected
FortinetFortiProxy7.6.0 <= 7.6.4affected
FortinetFortiProxy7.4.0 <= 7.4.11affected
FortinetFortiProxy7.2.0 <= 7.2.16affected
FortinetFortiProxy7.0.0 <= 7.0.23affected

Weaknesses

  • CWE-121: Execute unauthorized code or commands

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References