Insufficient Access Control Over API Endpoints

Summary

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiPortal may allow an authenticated attacker to view unauthorized device information via key modification in API requests.

Version Affected Solution
FortiPortal 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiPortal 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiPortal 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above

Acknowledgement

Fortinet is pleased to thank Pablo Castillo Andreu and Antonio Moreno from Telefonica Tech for reporting this vulnerability under responsible disclosure.

Timeline

2025-06-10: Initial publication