Buffer overread in authd and wad daemon

MonitorCVSS 4.1FG-IR-26-154Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A buffer over-read vulnerability exists in the authentication daemon (authd) and web access daemon (wad) of FortiOS and FortiProxy devices in the captive portal authentication processing code. The vulnerability allows an authenticated attacker to read beyond allocated memory boundaries, potentially leaking sensitive data such as configuration information, credentials, or session tokens. The issue affects FortiOS versions 7.2 (all), 7.4.0–7.4.8, and 7.6.0–7.6.2; FortiProxy versions 7.2 (all), 7.4.0–7.4.13, and 7.6.0–7.6.5. Fixed versions are available for all affected branches.

What this means
What could happen
A buffer overread in the authentication and web access daemon could allow an authenticated attacker to read sensitive memory from FortiOS or FortiProxy devices, potentially exposing configuration data, encryption keys, or session tokens that could be used to gain further access.
Who's at risk
Water utilities and electric utilities using Fortinet FortiOS or FortiProxy as perimeter security appliances or captive portal authentication systems. Any organization using these devices for employee or guest network access authentication is at risk if running affected versions.
How it could be exploited
An attacker with valid credentials (or access to a user account) can send a crafted request to the captive portal authentication process. The buffer overread in the authd/wad daemon reads beyond allocated memory boundaries, leaking sensitive data back in the response without requiring further privilege escalation.
Prerequisites
  • Valid user credentials or authenticated session on the FortiOS/FortiProxy device
  • Network access to the captive portal authentication interface (typically TCP 80/443)
  • Target device must be running affected FortiOS or FortiProxy versions (7.2.x, 7.4.0-7.4.8, 7.6.0-7.6.2 for FortiOS; 7.2.x, 7.4.0-7.4.13, 7.6.0-7.6.5 for FortiProxy)
Remotely exploitableRequires valid authentication credentialsLow-complexity attack (crafted request)Information disclosure (memory leak)Perimeter security device—compromise could expose internal network details
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
FortiOS7.6.0 - 7.6.27.6.4+
FortiOS7.4.0 - 7.4.87.4.9+
FortiOS7.2 all versionsMigrate to fixed release
FortiProxy7.6.0 - 7.6.57.6.6+
FortiProxy7.4.0 - 7.4.137.4.14+
FortiProxy7.2 all versionsMigrate to fixed release
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to the captive portal authentication interfaces (ports 80/443) to trusted user segments or internal networks only; implement firewall rules to block external access if not required
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS to version 7.6.4 or later, 7.4.9 or later, or migrate from 7.2.x to a fixed 7.4+ or 7.6+ release
FortiProxy
HOTFIXUpdate FortiProxy to version 7.6.6 or later, 7.4.14 or later, or migrate from 7.2.x to a fixed 7.4+ or 7.6+ release
All products
HARDENINGReview authentication logs and session records for indicators of unauthorized access or anomalous credential usage following this exposure disclosure
API: /api/v1/advisories/5ec4a8d7-f4aa-417f-a2b1-9452818ae08b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Buffer overread in authd and wad daemon | CVSS 4.1 - OTPulse