CVE-2025-53379

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information

Severity
High 7
CVSS 3.1
Exploited
Not listed
EPSS
0.004
31.2th percentile
Discovered by
Not disclosed
Published
Jul 14, 2026
Assigned by fortinet

Description

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

Weakness: CWE-125

Affected products

Vendor Product Category Matched by
Fortinet FortiAuthenticator Identity / IAM / MFA cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiAuthenticator

Vendor remediation

Upgrade to FortiAuthenticator version 6.6.3 or above