← Back

CVE-2025-59719

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Affected (3)

Products: Fortinet: Fortiweb
1 product
Fortiweb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.4.0 to 7.4.9
From 7.6.0 to 7.6.4
Version 8.0.0

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.