VYPR
High severity7.5NVD Advisory· Published Mar 24, 2025· Updated Jun 17, 2026

CVE-2021-26091

CVE-2021-26091

Description

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.

Affected products

3
  • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: >=6.2.0,<6.4.5
    • cpe:2.3:a:fortinet:fortimail:6.4.4:*:*:*:*:*:*:*range: 6.4.0
    • (no CPE)range: 6.4.0 - 6.4.4, 6.2.0 - 6.2.7

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.