---
id: CVE-2025-53950
title: >-
  An Exposure of Private Personal Information ('Privacy Violation')
  vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for
  MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4
  and 11.2.0 throug…
summary: >-
  An Exposure of Private Personal Information ('Privacy Violation')
  vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for
  MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4
  and 11.2.0 throug…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'
cwe:
  - CWE-359
vendor: fortinet
product: fortidlp_agent
affected:
  - 'fortidlp_agent >= 10.3.1, <= 11.5.1'
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53950'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-639'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.0018
epssPercentile: 0.0691
ingestedAt: '2026-10-09T12:53:28.982Z'
---

## Overview

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.

## Affected

- `fortidlp_agent >= 10.3.1, <= 11.5.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
