CVE-2025-53744: Incorrect Privilege Assignment in Security Fabric
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.
Other sources
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOS Security Fabric (FortiOS)to a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOS Security Fabric (FortiOS)to a version that resolves this vulnerability.Fixed in 7.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53744?
CVE-2025-53744 has been classified as a critical severity vulnerability.
How do I fix CVE-2025-53744?
To fix CVE-2025-53744, upgrade to FortiOS version 7.6.3 or higher, or 7.4.8 or higher depending on your current version.
Who is affected by CVE-2025-53744?
CVE-2025-53744 affects Fortinet's FortiOS versions between 6.4 and 7.6.2.
What type of vulnerability is CVE-2025-53744?
CVE-2025-53744 is an incorrect privilege assignment vulnerability.
Can an attacker exploit CVE-2025-53744 remotely?
Yes, a remote authenticated attacker can exploit CVE-2025-53744 if they have high privileges.