Executive brief
FortiAuthenticator is a centralized identity management appliance used to manage user authentication and single sign-on across a network. A security flaw in its web management interface could allow an unauthorized person to access sensitive system information by sending a specially crafted network request. This could lead to the exposure of data that might be used to further compromise the organization's security infrastructure.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GUI component of Fortinet FortiAuthenticator. The flaw is triggered when the application fails to properly validate the boundaries of a buffer while processing a specially crafted HTTP request. A remote, unauthenticated attacker can exploit this to read memory contents that should be inaccessible, potentially leading to the disclosure of sensitive information. The vulnerability affects versions 6.6.0 through 6.6.2 and all versions in the 6.5 branch. Users are advised to upgrade to version 6.6.3 or the upcoming 6.5.8 release.
Affected products
- Fortinet FortiAuthenticator 6.6.0 through 6.6.2, 6.5.0 through 6.5.7
Timeline
- 2026-07-14: disclosed: Initial publication of the advisory by Fortinet
- 2026-07-14: advisory: NVD record published