Privilege escalation from nginx user to root

Summary

An improper privilege management vulnerability [CWE-269] in FortiSOAR may allow a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.

Version Affected Solution
FortiSOAR on-premise 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiSOAR on-premise 7.0 7.0.0 through 7.0.2 Upgrade to 7.0.3 or above
FortiSOAR on-premise 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank security researchers Ryan Catterall and OJ Reeves of Beyond Binary for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2022-09-06: Initial publication