Fortinet FortiOS and FortiProxy Weak Key Derivation Vulnerability Allowing Backup Decryption

Vulnerability

A vulnerability exists in Fortinet FortiOS versions 7.4.0 through 7.4.3, 7.2 all versions, 7.0 all versions, 6.4 all versions, and FortiProxy versions 7.4.0 through 7.4.2, 7.2 all versions, 7.0 all versions, 2.0 all versions. This vulnerability involves the use of password hashes that lack sufficient computational effort, potentially allowing a privileged attacker with a super-admin profile and CLI access to decrypt backup files.

Impact

Exploitation of this vulnerability could lead to unauthorized decryption of backup files, allowing access to potentially sensitive information.

Remediation

Users can upgrade Fortinet FortiOS to version 7.4.4 or 7.2.9, depending on their current version. Fortinet FortiProxy users should upgrade to version 7.4.3. For versions 7.2, 7.0, and 2.0 all versions, users should migrate to a fixed release. Detailed upgrade instructions are available in Fortinet's upgrade tool.

Added: Apr 10, 2026, 3:00 PM
Updated: Apr 10, 2026, 3:00 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
3.0
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.