CVE Details

CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Published: 2026-07-27 CVSS: 5.3 MEDIUM Product: Fortinet FortiOS Due Date: 2026-08-10

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 5.3
  • Severity: MEDIUM
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: partial

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2025-68686
cveMetadata > assignerOrgId 6abe59d8-c742-4dff-8ce8-9b0ca1073da8
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName fortinet
cveMetadata > dateReserved 2025-12-23T15:55:12.376Z
cveMetadata > datePublished 2026-02-10T15:39:12.777Z
cveMetadata > dateUpdated 2026-07-27T19:50:49.592Z
containers > cna > affected > 0 > vendor Fortinet
containers > cna > affected > 0 > product FortiOS
containers > cna > affected > 0 > cpes > 0 cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 1 cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 2 cpe:2.3:o:fortinet:fortios:7.4.6:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 3 cpe:2.3:o:fortinet:fortios:7.4.5:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 4 cpe:2.3:o:fortinet:fortios:7.4.4:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 5 cpe:2.3:o:fortinet:fortios:7.4.3:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 6 cpe:2.3:o:fortinet:fortios:7.4.2:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 7 cpe:2.3:o:fortinet:fortios:7.4.1:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 8 cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 9 cpe:2.3:o:fortinet:fortios:7.2.13:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 10 cpe:2.3:o:fortinet:fortios:7.2.12:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 11 cpe:2.3:o:fortinet:fortios:7.2.11:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 12 cpe:2.3:o:fortinet:fortios:7.2.10:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 13 cpe:2.3:o:fortinet:fortios:7.2.9:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 14 cpe:2.3:o:fortinet:fortios:7.2.8:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 15 cpe:2.3:o:fortinet:fortios:7.2.7:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 16 cpe:2.3:o:fortinet:fortios:7.2.6:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 17 cpe:2.3:o:fortinet:fortios:7.2.5:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 18 cpe:2.3:o:fortinet:fortios:7.2.4:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 19 cpe:2.3:o:fortinet:fortios:7.2.3:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 20 cpe:2.3:o:fortinet:fortios:7.2.2:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 21 cpe:2.3:o:fortinet:fortios:7.2.1:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 22 cpe:2.3:o:fortinet:fortios:7.2.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 23 cpe:2.3:o:fortinet:fortios:7.0.19:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 24 cpe:2.3:o:fortinet:fortios:7.0.18:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 25 cpe:2.3:o:fortinet:fortios:7.0.17:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 26 cpe:2.3:o:fortinet:fortios:7.0.16:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 27 cpe:2.3:o:fortinet:fortios:7.0.15:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 28 cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 29 cpe:2.3:o:fortinet:fortios:7.0.13:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 30 cpe:2.3:o:fortinet:fortios:7.0.12:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 31 cpe:2.3:o:fortinet:fortios:7.0.11:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 32 cpe:2.3:o:fortinet:fortios:7.0.10:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 33 cpe:2.3:o:fortinet:fortios:7.0.9:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 34 cpe:2.3:o:fortinet:fortios:7.0.8:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 35 cpe:2.3:o:fortinet:fortios:7.0.7:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 36 cpe:2.3:o:fortinet:fortios:7.0.6:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 37 cpe:2.3:o:fortinet:fortios:7.0.5:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 38 cpe:2.3:o:fortinet:fortios:7.0.4:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 39 cpe:2.3:o:fortinet:fortios:7.0.3:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 40 cpe:2.3:o:fortinet:fortios:7.0.2:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 41 cpe:2.3:o:fortinet:fortios:7.0.1:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 42 cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 43 cpe:2.3:o:fortinet:fortios:6.4.16:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 44 cpe:2.3:o:fortinet:fortios:6.4.15:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 45 cpe:2.3:o:fortinet:fortios:6.4.14:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 46 cpe:2.3:o:fortinet:fortios:6.4.13:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 47 cpe:2.3:o:fortinet:fortios:6.4.12:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 48 cpe:2.3:o:fortinet:fortios:6.4.11:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 49 cpe:2.3:o:fortinet:fortios:6.4.10:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 50 cpe:2.3:o:fortinet:fortios:6.4.9:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 51 cpe:2.3:o:fortinet:fortios:6.4.8:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 52 cpe:2.3:o:fortinet:fortios:6.4.7:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 53 cpe:2.3:o:fortinet:fortios:6.4.6:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 54 cpe:2.3:o:fortinet:fortios:6.4.5:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 55 cpe:2.3:o:fortinet:fortios:6.4.4:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 56 cpe:2.3:o:fortinet:fortios:6.4.3:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 57 cpe:2.3:o:fortinet:fortios:6.4.2:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 58 cpe:2.3:o:fortinet:fortios:6.4.1:*:*:*:*:*:*:*
containers > cna > affected > 0 > cpes > 59 cpe:2.3:o:fortinet:fortios:6.4.0:*:*:*:*:*:*:*
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > versions > 0 > version 7.6.0
containers > cna > affected > 0 > versions > 0 > lessThanOrEqual 7.6.1
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 1 > versionType semver
containers > cna > affected > 0 > versions > 1 > version 7.4.0
containers > cna > affected > 0 > versions > 1 > lessThanOrEqual 7.4.6
containers > cna > affected > 0 > versions > 1 > status affected
containers > cna > affected > 0 > versions > 2 > versionType semver
containers > cna > affected > 0 > versions > 2 > version 7.2.0
containers > cna > affected > 0 > versions > 2 > lessThanOrEqual 7.2.13
containers > cna > affected > 0 > versions > 2 > status affected
containers > cna > affected > 0 > versions > 3 > versionType semver
containers > cna > affected > 0 > versions > 3 > version 7.0.0
containers > cna > affected > 0 > versions > 3 > lessThanOrEqual 7.0.19
containers > cna > affected > 0 > versions > 3 > status affected
containers > cna > affected > 0 > versions > 4 > versionType semver
containers > cna > affected > 0 > versions > 4 > version 6.4.0
containers > cna > affected > 0 > versions > 4 > lessThanOrEqual 6.4.16
containers > cna > affected > 0 > versions > 4 > status affected
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
containers > cna > providerMetadata > orgId 6abe59d8-c742-4dff-8ce8-9b0ca1073da8
containers > cna > providerMetadata > shortName fortinet
containers > cna > providerMetadata > dateUpdated 2026-02-10T15:39:12.777Z
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-200
containers > cna > problemTypes > 0 > descriptions > 0 > description Information disclosure
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity HIGH
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact NONE
containers > cna > metrics > 0 > cvssV3_1 > baseScore 5.3
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity MEDIUM
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact NONE
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
containers > cna > solutions > 0 > lang en
containers > cna > solutions > 0 > value Upgrade to FortiOS version 7.6.2 or above Upgrade to FortiOS version 7.4.7 or above
containers > cna > references > 0 > name https://fortiguard.fortinet.com/psirt/FG-IR-25-934
containers > cna > references > 0 > url https://fortiguard.fortinet.com/psirt/FG-IR-25-934
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-07-27T17:45:04.217591Z
containers > adp > 0 > metrics > 0 > other > content > id CVE-2025-68686
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact partial
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > type kev
containers > adp > 0 > metrics > 1 > other > content > dateAdded 2026-07-27
containers > adp > 0 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-07-27T19:50:49.592Z