Loading
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
Use CWE-338, Fortinet vendor hub and Fortimail product page to widen CVE-2021-26091 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-32756, CVE-2023-47539 and CVE-2024-46663 for nearby disclosures in the same product family.