Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please contact Technical Support within the FortiCare portal.

Secret/Launch

Bug ID

Description

1111984

Launching Web Account can be slow with Web Proxy enabled.

1111186

WebSSH console cannot copy/download.

1149599

The GUI page can occasionally become stuck after password verification.

1142546

Incorrect WebRDP/WebVNC URL with video recording disabled.

1120835, 1142262

Fixed an issue where the firewall policy for the service gateway can block WebSSH and WebSFTP when the request was sent using a new TCP connection.

1140540

Watchdog memory error in the password-change daemon.

1130735

Logic of folder permission changed impacting secret permissions.

1128897

Allow creating non-target based secret.

1122822, 1122835

Incorrect default personal folder settings.

1131259

User without permission for ZTNA tags cannot launch or save secret.

1130835

Email approval not working.

1045341

Random disconnections of the WebRDP connection.

User/Group

Bug ID

Description

1124133

2FA status check assertion issue.

1146150

3rd party 2FA QR code sent to multiple users unintentionally.

1140780

MFA bypass bug.

1142936

Getting logged in to FortiPAM as a different user.

1138555

SAML user login was unsuccessful due to incorrect group matching.

1151887

Issue when logging into the FortiPAM GUI with Microsoft Surface 7 and FortiToken.

System/Log

Bug ID

Description

1118634

Identifies video disk as a log disk.

1117515

FortiPAM ZTNA https deployment issue with FortiOS 7.4 and above.

1133597

One-time saved operation issues on interface GUI portal ZTNA control.

1159133

Recording bypass issue.

Others

Bug ID

Description

1116828

Enabling the GUI portal on a non-primary interface, e.g., port2, could prevent FortiPAM login due to incorrect firewall policies.

1120661

Integer Overflow on SSL-VPN VNC bookmark.

1121038

Weak authentication in WAD/GUI.

1112308, 1117737

Heap buffer overflow in websocket.

Common Vulnerabilities and Exposures

Bug ID

CVE references

1130288

FortiPAM is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2025-26466

  • CVE-2025-26465

Visit https://fortiguard.com/psirt for more information.

Resolved issues

Resolved issues

The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please contact Technical Support within the FortiCare portal.

Secret/Launch

Bug ID

Description

1111984

Launching Web Account can be slow with Web Proxy enabled.

1111186

WebSSH console cannot copy/download.

1149599

The GUI page can occasionally become stuck after password verification.

1142546

Incorrect WebRDP/WebVNC URL with video recording disabled.

1120835, 1142262

Fixed an issue where the firewall policy for the service gateway can block WebSSH and WebSFTP when the request was sent using a new TCP connection.

1140540

Watchdog memory error in the password-change daemon.

1130735

Logic of folder permission changed impacting secret permissions.

1128897

Allow creating non-target based secret.

1122822, 1122835

Incorrect default personal folder settings.

1131259

User without permission for ZTNA tags cannot launch or save secret.

1130835

Email approval not working.

1045341

Random disconnections of the WebRDP connection.

User/Group

Bug ID

Description

1124133

2FA status check assertion issue.

1146150

3rd party 2FA QR code sent to multiple users unintentionally.

1140780

MFA bypass bug.

1142936

Getting logged in to FortiPAM as a different user.

1138555

SAML user login was unsuccessful due to incorrect group matching.

1151887

Issue when logging into the FortiPAM GUI with Microsoft Surface 7 and FortiToken.

System/Log

Bug ID

Description

1118634

Identifies video disk as a log disk.

1117515

FortiPAM ZTNA https deployment issue with FortiOS 7.4 and above.

1133597

One-time saved operation issues on interface GUI portal ZTNA control.

1159133

Recording bypass issue.

Others

Bug ID

Description

1116828

Enabling the GUI portal on a non-primary interface, e.g., port2, could prevent FortiPAM login due to incorrect firewall policies.

1120661

Integer Overflow on SSL-VPN VNC bookmark.

1121038

Weak authentication in WAD/GUI.

1112308, 1117737

Heap buffer overflow in websocket.

Common Vulnerabilities and Exposures

Bug ID

CVE references

1130288

FortiPAM is no longer vulnerable to the following CVE-Reference(s):

  • CVE-2025-26466

  • CVE-2025-26465

Visit https://fortiguard.com/psirt for more information.