CVE-2025-59923: Low severity Fortinet FortiAuthenticator vulnerability
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59923?
CVE-2025-59923 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-59923?
To fix CVE-2025-59923, update Fortinet FortiAuthenticator to a version higher than 6.6.4.
What type of vulnerability is CVE-2025-59923?
CVE-2025-59923 is an improper access control vulnerability.
Who is affected by CVE-2025-59923?
CVE-2025-59923 affects authenticated users with read-only admin permissions in specified versions of FortiAuthenticator.
Can CVE-2025-59923 be exploited remotely?
Exploitation of CVE-2025-59923 requires authenticated access, thus it cannot be exploited remotely without valid credentials.