Fortinet FortiOS LDAP Credential Decryption Vulnerability

Vulnerability

A vulnerability in Fortinet FortiOS versions through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files. This issue arises because the encryption key is static and identical across all customer installations, leading to unauthorized access to sensitive information. The vulnerability has been actively exploited since December 16, 2025.

Impact

Exploitation of this vulnerability allows for the unauthorized decryption of LDAP connection passwords, which FortiGate appliances use to authenticate with LDAP servers. This could lead to unauthorized access or manipulation of resources within the LDAP directory.

Reproduction

The vulnerability can be reproduced by accessing the FortiGate device's configuration files, which contain LDAP credentials encrypted with a default key. This key can be used to decrypt the passwords, particularly for devices running FortiOS 7.6.5.

Remediation

Fortinet recommends enabling the 'private-data-encryption' feature on FortiGate devices, which replaces the default encryption key with a custom one. This step is crucial for protecting sensitive credentials and is officially advised as a hardening measure.

Added: Feb 5, 2026, 10:20 PM
Updated: Feb 5, 2026, 10:20 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.3
remediation
8.3
relevance
2.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.