CVE-2025-54822

An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

History

14 Jan 2026, 10:16

Type Values Removed Values Added
Summary (en) An improper authorization vulnerability [CWE-285] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.8 & Fortinet FortiProxy before version 7.4.8 allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests. (en) An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.

15 Oct 2025, 17:20

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortios
Fortinet fortiproxy
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-684 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-684 - Vendor Advisory

14 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 16:15

Updated : 2026-01-14 10:16


NVD link : CVE-2025-54822

Mitre link : CVE-2025-54822

CVE.ORG link : CVE-2025-54822


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortios
CWE
CWE-285

Improper Authorization