CVE-2026-22572
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)
Description
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Affected (6)
Products: Fortinet: Fortianalyzer, Fortimanager, Fortimanager Cloud
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2.2 to 7.4.8 | |
| From 7.2.2 to 7.4.8 | |
| From 7.2.2 to 7.4.8 |
References (1)
Timeline
No history available yet.