Missing authorization on log access

Summary

A Direct Request ('Forced Browsing') [CWE-425] vulnerability in FortiAuthenticator logs may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints.

Version Affected Solution
FortiAuthenticator 8.0 Not affected Not Applicable
FortiAuthenticator 6.6 6.6.0 through 6.6.6 Upgrade to 6.6.7 or above
FortiAuthenticator 6.5 6.5 all versions Migrate to a fixed release
FortiAuthenticator 6.4 6.4 all versions Migrate to a fixed release
FortiAuthenticator 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Discovered during an independent audit commissioned by Fortinet.

Timeline

2025-12-09: Initial publication