PT-2025-50122 · Fortinet · Fortiauthenticator

Published

2025-12-09

·

Updated

2025-12-11

·

CVE-2025-59923

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAuthenticator versions 6.3 through 6.6.6 Fortinet FortiAuthenticator 6.5 all versions Fortinet FortiAuthenticator 6.4 all versions
Description An access control issue exists in FortiAuthenticator that may allow an authenticated attacker with read-only admin permission to obtain the credentials of other administrators' messaging services through specially crafted requests.
Recommendations FortiAuthenticator versions prior to 6.6.7 should be updated. FortiAuthenticator version 6.6.6 should be updated. FortiAuthenticator version 6.5 should be updated. FortiAuthenticator version 6.4 should be updated. FortiAuthenticator version 6.3 should be updated.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-59923

Affected Products

Fortiauthenticator