CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Platform
FortiGate / FortiOS
CVE Record
CVE-2026-24858
Advisory
CISA-KEV
Published
27 January 2026
Views
39
Primary source: Review the official advisory at nvd.nist.gov
Go to Source
Status
Bu açık CISA tarafından aktif istismar edildiği doğrulanmış açıklar katalogunda yer alıyor. Teorik bir risk değil — sahada kullanılıyor.
Description
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Details
Vendor: Fortinet
Product: Multiple Products
Katalog'a eklenme: 2026-01-27
CISA'nın Zorunlu Kıldığı Aksiyon
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CVSSv3 Score: 7.3 An improper certificate validation vulnerability in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00
CVSSv3 Score: 4.7 An improper access control vulnerability in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00