Unrated severityNVD Advisory· Published Dec 9, 2025· Updated Jan 14, 2026
CVE-2025-59923
CVE-2025-59923
Description
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.
Affected products
2- Fortinet/FortiAuthenticatorv5cpe:2.3:a:fortinet:fortiauthenticator:6.6.6:*:*:*:*:*:*:*Range: 6.6.0
- Range: 6.6.0 through 6.6.6, 6.5 all versions, 6.4 all versions, 6.3 all versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.