CVE-2026-25815 Details
Description
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option.
A vulnerability in Fortinet FortiOS versions through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files. This issue arises because the encryption key is static and identical across all customer installations, leading to unauthorized access to sensitive information. The vulnerability has been actively exploited since December 16, 2025.
Fortinet recommends enabling the 'private-data-encryption' feature on FortiGate devices, which replaces the default encryption key with a custom one. This step is crucial for protecting sensitive credentials and is officially advised as a hardening measure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 5, 2026CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1394 | Use of Default Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fortinet FortiOS | <= 7.6.6 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | New CVE Received | [email protected] |
Volerion