CVE-2019-15707: Fortinet FortiMail

Medium severity, CVSS 4.9. EPSS: 1.3% chance of exploitation in the next 30 days.

An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.

Affected products

  • Fortinet FortiMail: up to and including 5.4.10; from 6.0.0, up to and including 6.0.6; version 6.2.0 only

Published 2020-01-23. Last modified 2026-06-17.