Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
High Listed in CISA KEV
Summary
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Fortinet:Multiple Products
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-24858 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://fortiguard.fortinet.com/psirt/FG-IR-26-060 reference
- https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV