Incorrect authorization in multi-vdom environment

Summary

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

Version Affected Solution
FortiPortal 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiPortal 7.2 Not affected Not Applicable
FortiPortal 7.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Hisham AboulMakarem of Fortinet Systems Engineer team.

Timeline

2025-12-09: Initial publication