Executive brief
A security vulnerability exists in Fortinet FortiOS, the operating system used to manage FortiGate firewalls and network security devices. An authorized user could potentially view sensitive information stored in the device's memory by sending a specially crafted web request. This could lead to the exposure of internal system data, though it requires the attacker to already have a valid login to the system.
Technical details
A buffer over-read vulnerability (CWE-126) exists in Fortinet FortiOS versions 7.2, 7.4, and 7.6. The flaw is triggered when the system processes a specially crafted request that results in a redirect response. An authenticated remote attacker with low privileges can exploit this to leak portions of the device's memory. The leaked memory is returned within the redirect response, potentially exposing sensitive information. Users are advised to upgrade to patched versions of FortiOS as specified by the vendor.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory