CVE-2023-36556 HIGH

CVE-2023-36556

Vendor Fortinet
Product FortiMail
Weakness CWE-863 · Incorrect authorization
Published October 10, 2023
Last update December 16, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C

What the vulnerability does

01Description

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

Key dates

02Disclosure timeline

October 10, 2023 CVE published
December 16, 2025 Record updated