Critical SEVERITY — Vulnerability

JWT used for authentication in web GUI signed with static key

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
9.6/10
Advisory
FG-IR-26-170
Published
08 September 2026
Views
47
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →