---
id: CVE-2025-57823
title: >-
  A direct request ('forced browsing') vulnerability in Fortinet
  FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions,
  FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may
  allow an authenticat…
summary: >-
  A direct request ('forced browsing') vulnerability in Fortinet
  FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions,
  FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may
  allow an authenticat…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-425
vendor: fortinet
product: fortiauthenticator
affected:
  - 'fortiauthenticator >= 6.3.0, <= 6.6.6'
published: '2025-12-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-57823'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-554'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.12653
ingestedAt: '2026-09-30T23:29:32.483Z'
---

## Overview

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

## Affected

- `fortiauthenticator >= 6.3.0, <= 6.6.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
