Improper access control in API endpoints

Summary

An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests.

Version Affected Solution
FortiPortal 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiPortal 7.2 7.2.0 through 7.2.8 Upgrade to 7.2.9 or above
FortiPortal 7.0 7.0 all versions Migrate to a fixed release

Timeline

2026-06-09: Initial publication