Privilege escalation in shell

Summary

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR may allow an attacker who has already obtained a non-login low privileged shell access to perform a local privilege escalation via crafted commands.

Version Affected Solution
FortiSOAR on-premise 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiSOAR on-premise 7.5 7.5.0 through 7.5.1 Upgrade to 7.5.2 or above
FortiSOAR on-premise 7.4 7.4 all versions Migrate to a fixed release
FortiSOAR on-premise 7.3 7.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Boumediene Kaddour from Fortinet FortiGuard labs team. Fortinet is also pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.

Timeline

2025-10-14: Initial publication