An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to FortiSOAR Agent Communication Bridge version 1.1.1 or above


Workaround

No workaround given by the vendor.

History

Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Description An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.
First Time appeared Fortinet
Fortinet fortisoaragentcommunicationbridge
Weaknesses CWE-22
CPEs cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.1.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisoaragentcommunicationbridge
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N/E:F/RL:X/RC:R'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-03-10T17:41:32.111Z

Reserved: 2025-07-28T09:23:38.063Z

Link: CVE-2025-54659

cve-icon Vulnrichment

Updated: 2026-03-10T17:34:22.767Z

cve-icon NVD

Status : Received

Published: 2026-03-10T18:17:58.200

Modified: 2026-03-10T18:17:58.200

Link: CVE-2025-54659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses