← Back to CVE List
Vulnerability Intelligence Report
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-24858

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:85.84%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-288 ↗Improper access control

Affected Products & Versions

Vendor Product Affected Versions
Fortinet FortiWeb 8.0.0 <= 8.0.3 (affected), 7.6.0 <= 7.6.6 (affected), 7.4.0 <= 7.4.11 (affected)
Fortinet FortiNAC-F 7.6.3 <= 7.6.5 (affected)
Fortinet FortiOS 7.6.0 <= 7.6.5 (affected), 7.4.0 <= 7.4.10 (affected), 7.2.0 <= 7.2.12 (affected), 7.0.0 <= 7.0.18 (affected)
Fortinet FortiAnalyzer 7.6.0 <= 7.6.5 (affected), 7.4.0 <= 7.4.9 (affected), 7.2.0 <= 7.2.11 (affected), 7.0.0 <= 7.0.15 (affected)
Fortinet FortiProxy 7.6.0 <= 7.6.4 (affected), 7.4.0 <= 7.4.12 (affected), 7.2.0 <= 7.2.15 (affected), 7.0.0 <= 7.0.22 (affected)
Fortinet FortiManager 7.6.0 <= 7.6.5 (affected), 7.4.0 <= 7.4.9 (affected), 7.2.0 <= 7.2.11 (affected), 7.0.0 <= 7.0.15 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
85.844%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityFortinet, Inc. · Vendor · USA
Reserved2026-01-27T15:11:02
Published2026-01-27T19:18:23
Last Updated2026-06-09T14:27:53

LINK COPIED TO CLIPBOARD