FORTINET Security Advisory

Published Date: June 10, 2025 | Revised on June 15, 2026

Advisory Summary

๐Ÿ”” Security Alert: Information Disclosure Vulnerability in FortiOS SSL-VPN Web-Mode

Fortinet has disclosed a vulnerability classified as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) affecting its FortiOS SSL-VPN web-mode. This issue, assigned a CVSSv3 score of 3.9, allows an authenticated user to potentially access full SSL-VPN settings through a specifically crafted URL. Although the risk level is moderate, this vulnerability could reveal critical configuration details to malicious insiders or compromised accounts, posing a threat to the integrity and confidentiality of VPN deployments.

This incident underscores the importance of vigilance even when users are authenticated, as insider and session-based risks remain prevalent. Fortinetโ€™s timely revision and disclosure emphasize their commitment to safeguarding client infrastructures.

๐Ÿ”—

Reference: Vendor Advisory