Read-only admin could obtain admin configuration secrets

Summary

An improper access control vulnerability [CWE-284] in FortiAuthenticator Web UI may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.

Version Affected Solution
FortiAuthenticator 8.0 Not affected Not Applicable
FortiAuthenticator 6.6 6.6.0 through 6.6.6 Upgrade to 6.6.7 or above
FortiAuthenticator 6.5 6.5 all versions Migrate to a fixed release
FortiAuthenticator 6.4 6.4 all versions Migrate to a fixed release
FortiAuthenticator 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Dino-Boris Dougoud of the Fortinet Sales team and Eric Wang of the Fortinet Corporate InfoSec team.

Timeline

2025-12-09: Initial publication