Heap-based buffer overflow in oftpd daemon

Summary

A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation

Version Affected Solution
FortiAnalyzer Cloud 7.6 7.6.2 through 7.6.4 Upgrade to 7.6.5 or above
FortiManager Cloud 7.6 7.6.2 through 7.6.4 Upgrade to 7.6.5 or above

Thanks to network segmentation, this vulnerability could only be exploited if the attacker has already access to another cloud component belonging to the same entity.

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2026-04-14: Initial publication