Arbitrary file overwrite in FGFMd

Summary

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiManager & FortiManager Cloud may allow an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

Version Affected Solution
FortiManager 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiManager 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiManager 7.2 7.2.0 through 7.2.9 Upgrade to 7.2.10 or above
FortiManager 7.0 7.0.0 through 7.0.13 Upgrade to 7.0.14 or above
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager 6.2 6.2 all versions Migrate to a fixed release
FortiManager Cloud 7.6 Not affected Not Applicable
FortiManager Cloud 7.4 7.4.1 through 7.4.5 Upgrade to 7.4.6 or above
FortiManager Cloud 7.2 7.2.1 through 7.2.9 Upgrade to 7.2.10 or above
FortiManager Cloud 7.0 7.0.1 through 7.0.13 Migrate to a fixed release
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Timeline

2025-08-12: Initial publication
2025-08-13: FortiManager is fixed in 7.4.6