CVE-2025-55717: Fortinet FortiMail
Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Affected products
- Fortinet FortiMail: from 7.0.0, before 7.0.9 (fixed in 7.0.9); from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.4.0, before 7.4.5 (fixed in 7.4.5); from 7.6.0, before 7.6.3 (fixed in 7.6.3)
- Fortinet Fortirecorder: from 6.4.0, before 7.2.4 (fixed in 7.2.4)
- Fortinet Fortivoice: from 7.0.0, before 7.0.7 (fixed in 7.0.7); version 7.2.0 only
Published 2026-03-10. Last modified 2026-06-17.