Path traversal in Solution Pack upload

Summary

A relative path traversal vulnerability [CWE-23] in FortiSOAR may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.

Version Affected Solution
FortiSOAR on-premise 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiSOAR on-premise 7.5 7.5.0 through 7.5.1 Upgrade to 7.5.2 or above
FortiSOAR on-premise 7.4 7.4 all versions Migrate to a fixed release
FortiSOAR on-premise 7.3 7.3 all versions Migrate to a fixed release
FortiSOAR on-premise 7.2 Not affected Not Applicable
FortiSOAR on-premise 7.0 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.

Timeline

2025-08-12: Initial publication