---
cve: "CVE-2026-71407"
severity: "MEDIUM"
cvss: 5.1
epss: "0.5%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2026-08-12 13:17:25"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T15:18:03+02:00"
---

# CVE-2026-71407

> 5.1 MEDIUM

## Beschreibung

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Schwachstellen-Klasse

- **CWE-121** — Stack-based Buffer Overflow
  A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-26-161>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-71407) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
