Debug endpoint can display password in clear text

Summary

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiADC may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiADC 8.0 Not affected Not Applicable
FortiADC 7.6 Not affected Not Applicable
FortiADC 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiADC 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiADC 7.1 7.1.0 through 7.1.4 Upgrade to 7.1.5 or above
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Kushal Shah of Fortinet Vulnerability Research team.

Timeline

2025-10-14: Initial publication