LDAP Credential Decryption Vulnerability in Fortinet FortiOS
CVE-2026-25815

3.2LOW

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
5 February 2026

What is CVE-2026-25815?

Fortinet FortiOS versions up to 7.6.6 are susceptible to a vulnerability that allows unauthorized entities to decrypt LDAP credentials stored within device configuration files. This security flaw has been actively exploited since December 16, 2025, due to the consistent use of a single encryption key across all installations. Although Fortinet asserts that customers are meant to activate a non-default encryption option that mitigates this issue, enabling such an option can disrupt system functionality as highlighted in the management guidelines for FortiGates. This indicates that many users may remain exposed if they do not adjust their settings accordingly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

FortiOS 0 <= 7.6.6

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.