CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Platform
FortiGate / FortiOS
CVE Kaydı
CVE-2026-24858
Advisory
CISA-KEV
Yayın Tarihi
27 Ocak 2026
Okunma
2
Birincil kaynak: Kaynaktaki resmî duyuruyu inceleyin: nvd.nist.gov
Kaynağa Git
Durum
Bu açık CISA tarafından aktif istismar edildiği doğrulanmış açıklar katalogunda yer alıyor. Teorik bir risk değil — sahada kullanılıyor.
Açıklama
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Künye
Üretici: Fortinet
Ürün: Multiple Products
Katalog'a eklenme: 2026-01-27
CISA'nın Zorunlu Kıldığı Aksiyon
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.