CVE-2021-26095

HIGH

FortiMail <6.4.4/<6.2.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-019

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
fortinet/fortimail 6.2.0 - 6.2.6
Published Jul 20, 2021
Tracked Since Feb 18, 2026