---
id: CVE-2025-59921
title: >-
  An exposure of sensitive information to an unauthorized actor vulnerability
  [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version
  7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated
  att…
summary: >-
  An exposure of sensitive information to an unauthorized actor vulnerability
  [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version
  7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated
  att…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: fortinet
product: fortiadc
affected:
  - 'fortiadc >= 6.2.0, < 7.1.5'
  - 'fortiadc >= 7.2.0, < 7.2.4'
  - fortiadc = 7.4.0
patched:
  - fortiadc 7.2.4
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59921'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-434'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00303
epssPercentile: 0.21093
ingestedAt: '2026-10-08T11:31:27.391Z'
---

## Overview

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.

## Affected

- `fortiadc >= 6.2.0, < 7.1.5`
- `fortiadc >= 7.2.0, < 7.2.4`
- `fortiadc = 7.4.0`

## Remediation

Upgrade past the affected range:

- `fortiadc 7.2.4`
