FG-IR-26-154: Buffer overread in authd and wad daemon
Published Jul 14, 2026
·Updated
A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Affected Software
9 affected componentsFixes available
Fortinet FortiOS>=7.6.0<=7.6.3
Fortinet FortiOS>=7.4.0<=7.4.8
Fortinet FortiOS>=7.2
Fortinet FortiOS>=7.0
Fortinet FortiOS>=6.4
Fortinet FortiProxy>=7.6.0<=7.6.5
Fortinet FortiProxy>=7.4.0<=7.4.13
Fortinet FortiProxy>=7.2
Fortinet FortiProxy>=7.0
Event History
Jul 14, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-154?
The severity of FG-IR-26-154 is medium, rated at 4.1.
2
How do I fix FG-IR-26-154?
To fix FG-IR-26-154, ensure that you update your FortiOS or FortiProxy to the latest patched version.
3
What types of systems are affected by FG-IR-26-154?
FG-IR-26-154 affects Fortinet FortiOS and Fortinet FortiProxy systems.
4
What is the risk associated with FG-IR-26-154?
The risk associated with FG-IR-26-154 includes an authenticated remote attacker potentially accessing sensitive information from device memory.
5
What does the buffer over-read vulnerability in FG-IR-26-154 allow?
The buffer over-read vulnerability in FG-IR-26-154 allows returning a portion of device memory in response to specially crafted requests.