Description
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
Published: 2025-12-09
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to FortiAuthenticator version 8.0.0 or above Upgrade to FortiAuthenticator version 6.6.7 or above

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.4, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests. An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
CPEs cpe:2.3:a:fortinet:fortiauthenticator:6.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.6:*:*:*:*:*:*:*

Tue, 09 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*

Tue, 09 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.4, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
First Time appeared Fortinet
Fortinet fortiauthenticator
Weaknesses CWE-284
CPEs cpe:2.3:a:fortinet:fortiauthenticator:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.4:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiauthenticator
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:C'}


Subscriptions

Fortinet Fortiauthenticator
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-01-14T09:18:46.546Z

Reserved: 2025-09-23T12:51:54.672Z

Link: CVE-2025-59923

cve-icon Vulnrichment

Updated: 2025-12-09T20:21:32.513Z

cve-icon NVD

Status : Modified

Published: 2025-12-09T18:15:55.663

Modified: 2025-12-11T17:15:56.497

Link: CVE-2025-59923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses