CVE-2025-53379
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information
Severity
High 7
CVSS 3.1
Exploited
Not listed
EPSS
0.004
31.2th percentile
Discovered by
Not disclosed
Published
Jul 14, 2026
Assigned by fortinet
Description
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
Weakness: CWE-125
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAuthenticator | Identity / IAM / MFA | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiAuthenticator
Vendor remediation
Upgrade to FortiAuthenticator version 6.6.3 or above