CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a…
How it works
The weakness is classified as CWE-288, authentication bypass using an alternate path or channel. When FortiCloud SSO is active, the product accepts authentication assertions from the FortiCloud service for any registered device.
- An attacker who already controls a FortiCloud account can leverage the trust relationship created for their own device.
- That trust is then used to reach additional devices registered under other accounts, bypassing the normal per-account authentication checks.
Am I affected? How to find it in your systems
FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are deployed as physical or virtual appliances that perform logging, management, firewall, and proxy functions. Inventory every instance of these products and determine whether FortiCloud SSO authentication is enabled on each one. Specific version numbers and configuration settings that trigger the issue must be confirmed against the vendor advisory.
- Examine device configuration files or the management interface for FortiCloud SSO settings.
- Review authentication logs for entries that originate from FortiCloud identity assertions.
How to remediate
Apply the vendor update referenced in the official advisory. After the update is installed, review all devices that previously used FortiCloud SSO and disable the feature unless it is explicitly required. Follow any additional configuration guidance supplied by the vendor for this class of authentication issue.
If you can't patch immediately
Disable FortiCloud SSO authentication on affected devices where operationally acceptable. Restrict network access to management interfaces so that only trusted administrative networks can reach them. Monitor authentication and session logs for unexpected FortiCloud-originated logins. Apply mitigations according to the vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
If your data may have been exposed
Vulnerabilities that allow unauthorized access can result in data exposure or further compromise of the affected systems. Organizations can run a free exposure scan of their email addresses to check against known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.