FGFM Authentication Weakening via CLI Configuration
CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00