Credential leakage through debug commands

Summary

An insufficiently protected credentials vulnerability [CWE-522] in FortiExtender may allow an authenticated user to obtain administrator credentials via debug log commands.

Version Affected Solution
FortiExtender 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.3 or above
FortiExtender 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.8 or above
FortiExtender 7.2 7.2 all versions Migrate to a fixed release
FortiExtender 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by David Maciejak of the Fortinet product security team

Timeline

2025-11-18: Initial publication