# CVE-2026-25815

## Summary

- **CVE ID:** CVE-2026-25815
- **Severity:** LOW
- **CVSS Score:** 3.2 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)
- **CWE:** CWE-1394
- **Published:** Feb 5, 2026
- **Last Modified:** Mar 12, 2026

## Description

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option.

## Affected Products

- Fortinet — FortiOS (0)

## References

- [CNA](https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-ldap-connection-passwords)
- [CNA](https://docs.fortinet.com/document/fortimanager/7.6.6/administration-guide/30332/managing-fortigates-with-private-data-encryption)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._