HarborGuard / CVE
Back to search
CRITICALCVE-2026-24858Published Modified CNA fortinet

CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Metrics

CVSS v3.1
9.4
Severity
CRITICAL
Fixed in
*
Affected Products
5

Fix available

*
Affected packages
  • Fortinet / FortiOS
    ≤ 7.6.5 · ≤ 7.4.10 · ≤ 7.2.12 · ≤ 7.0.18
  • Fortinet / FortiManager
    ≤ 7.6.5 · ≤ 7.4.9 · ≤ 7.2.11 · ≤ 7.0.15
  • Fortinet / FortiAnalyzer
    ≤ 7.6.5 · ≤ 7.4.9 · ≤ 7.2.11 · ≤ 7.0.15
  • Fortinet / FortiProxy
    ≤ 7.6.4 · ≤ 7.4.12 · ≤ 7.2.15 · ≤ 7.0.22
  • Fortinet / FortiWeb
    ≤ 8.0.3 · ≤ 7.6.6 · ≤ 7.4.11
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C