Back

MEDIUM

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command

Published Nov 18, 2025

Description

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.

Affected products

Remediation

Vendor solution

Fortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action. Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.12 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to upcoming FortiProxy version 7.4.14 or above Upgrade to FortiPAM version 1.7.0 or above Upgrade to FortiPAM version 1.6.1 or above

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Nov 18, 2025
Updated Aug 11, 2026
Reserved Jul 30, 2025
CISA Vulnrichment
Updated Nov 18, 2025
NVD
Status Modified
Modified Jun 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner fortinet
Published Nov 18, 2025
Updated Aug 11, 2026
Exploited since n/a
EUVD-2025-198008