Stack-based Buffer Overflow in Fortinet FortiOS Products
CVE-2026-71407
5.1MEDIUM
What is CVE-2026-71407?
A stack-based buffer overflow vulnerability exists in Fortinet's FortiOS versions 7.6.1 to 7.6.6. This flaw allows unauthenticated attackers to potentially execute arbitrary code or commands within the context of the WAD daemon. The vulnerability is exploitable only when the explicit proxy is configured with Kerberos authentication and SOCKS is enabled. Attackers can leverage crafted sockets to bypass stack protection and address space layout randomization (ASLR), posing a significant security risk.
Affected Version(s)
FortiOS 7.6.1 <= 7.6.6
FortiPAM 1.8.0 <= 1.8.4
FortiPAM 1.7.0 <= 1.7.2