An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests
History

Wed, 15 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure via Crafted HTTP Requests in FortiNDR and FortiVoice

Tue, 14 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Description An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests
First Time appeared Fortinet
Fortinet fortindr
Fortinet fortivoice
Weaknesses CWE-200
CPEs cpe:2.3:a:fortinet:fortindr:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:7.0.1:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortindr
Fortinet fortivoice
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-04-14T16:46:15.501Z

Reserved: 2024-01-11T16:29:07.978Z

Link: CVE-2024-23104

cve-icon Vulnrichment

Updated: 2026-04-14T16:37:12.718Z

cve-icon NVD

Status : Received

Published: 2026-04-14T16:16:28.723

Modified: 2026-04-14T16:16:28.723

Link: CVE-2024-23104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T15:30:06Z