Path Traversal Vulnerability in Fortinet FortiSOAR Agent Communication Bridge
CVE-2025-54659
5.5MEDIUM
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2025-54659?
A path traversal vulnerability exists within Fortinet's FortiSOAR Agent Communication Bridge, allowing unauthenticated attackers to craft malicious requests that may gain access to files on the system. This occurs through the agent port, where improperly limited pathname restrictions permit access to files designated for the fortisoar user, exposing sensitive information.
Affected Version(s)
FortiSOAR Agent Communication Bridge 1.1.0
FortiSOAR Agent Communication Bridge 1.0.0 <= 1.0.2