fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-26-146 CVE-2025-53379
HIGH
Fortinet FortiAuthenticator Out-of-Bounds Read Information Disclosure
Record summary
CVE-2025-53379 has a selected CVSS score of 7.0 (high).
Description
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiAuthenticatorBrowse Fortinet / FortiAuthenticatorDefault status: unaffected | CVE List | 6.6.0 to ≤ 6.6.2 | affected |
| 6.5.0 to ≤ 6.5.7 | affected | ||
| 6.4.0 to ≤ 6.4.11 | affected | ||
| 6.3.0 to ≤ 6.3.5 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-53379