Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to FortiSOAR Agent Communication Bridge version 1.1.1 or above
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-084 |
|
Thu, 09 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortisoar Agent Communication Bridge
|
|
| CPEs | cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoar_agent_communication_bridge:1.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet fortisoar Agent Communication Bridge
|
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port. | |
| First Time appeared |
Fortinet
Fortinet fortisoaragentcommunicationbridge |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.0.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaragentcommunicationbridge:1.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortisoaragentcommunicationbridge |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-03-10T17:41:32.111Z
Reserved: 2025-07-28T09:23:38.063Z
Link: CVE-2025-54659
Updated: 2026-03-10T17:34:22.767Z
Status : Analyzed
Published: 2026-03-10T18:17:58.200
Modified: 2026-04-09T20:56:21.100
Link: CVE-2025-54659
No data.
OpenCVE Enrichment
Updated: 2026-03-11T11:49:13Z