CVE-2025-53744
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
- EPSS probability
- 0.61%
- CWE
- CWE-266
- Published
- 2025-08-12
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2026-78477 — The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak
- CVE-2026-84814 — WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
- CVE-2026-81294 — WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability
- CVE-2026-78330 — Apache Syncope: Privilege escalation for admin user via JWT authentication
- CVE-2026-78267 — WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability
- CVE-2026-73390 — WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability
- CVE-2026-73347 — WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability
- CVE-2026-66682 — WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability