Executive brief
A security vulnerability exists in Fortinet's FortiOS Security Fabric, a system used to coordinate security across different network devices. An attacker who already has high-level administrative access could exploit this flaw to gain full 'super-admin' control over the system. This is achieved by tricking the device into registering with a malicious management server, potentially allowing the attacker to bypass all security restrictions and gain total control over the network infrastructure.
Technical details
An incorrect privilege assignment vulnerability (CWE-266) exists within the Security Fabric component of Fortinet FortiOS. The flaw allows a remote authenticated attacker who already possesses high-level privileges to escalate their access to 'super-admin' status. The attack is executed by registering the affected device to a malicious, attacker-controlled FortiManager instance. This vulnerability affects multiple major versions of FortiOS, including 6.4, 7.0, 7.2, 7.4, and 7.6. Patches are available in FortiOS versions 7.6.3 and 7.4.8, while users on older branches are advised to migrate to a fixed release.
Affected products
- Fortinet FortiOS Security Fabric 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Siemens RUGGEDCOM APE1808 (Fortigate NGFW) Versions with Fortigate NGFW < V7.4.9 or < V7.6.6
Timeline
- 2025-08-12: disclosed: Initial publication by Fortinet
- 2025-08-12: advisory: Fortinet advisory FG-IR-25-173 published
- 2026-06-09: other: Last modified date in NVD record