CVE-2025-54659

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.1:*:*:*:*:*:*:*

History

09 Apr 2026, 20:56

Type Values Removed Values Added
First Time Fortinet
Fortinet fortisoar Agent Communication Bridge
Summary
  • (es) Una limitación inadecuada de un nombre de ruta a un directorio restringido ('Salto de ruta') vulnerabilidad [CWE-22] vulnerabilidad en Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 todas las versiones puede permitir a un atacante no autenticado leer archivos accesibles para el usuario fortisoar en un sistema donde el agente está desplegado, mediante el envío de una solicitud manipulada al puerto del agente.
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-084 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-084 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.1:*:*:*:*:*:*:*

10 Mar 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:17

Updated : 2026-06-17 09:40


NVD link : CVE-2025-54659

Mitre link : CVE-2025-54659

CVE.ORG link : CVE-2025-54659


JSON object : View

Products Affected

fortinet

  • fortisoar_agent_communication_bridge
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')