CVE-2025-54659: Fortinet Fortisoar Agent Communication Bridge

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a system where the agent is deployed, via sending a crafted request to the agent port.

Affected products

  • Fortinet Fortisoar Agent Communication Bridge: version 1.0 only; version 1.1 only

Published 2026-03-10. Last modified 2026-06-17.