SB20260414122 - Insufficiently protected credentials in FortiSandbox
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficiently protected credentials (CVE-ID: CVE-2026-27316)
The vulnerability allows a remote privileged user to gain access to sensitive information.
The vulnerability exists due to insufficiently protected credentials in LDAP configuration web page. An authenticated administrator can read LDAP server credentials via client-side inspection.
Remediation
Install update from vendor's website.