← Back

CVE-2026-24858

nvd nist
Published: Jan 27, 2026Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Affected (21)

6 products
Fortianalyzer
Fortimanager
Fortinac F
Fortios
Fortiproxy
Fortiweb
1 product
Ruggedcom Ape1808 Firmware
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.0.15
From 7.2.0 to 7.2.11
From 7.4.0 to 7.4.10
From 7.6.0 to 7.6.6
Fortinet
From 7.0.0 to 7.0.15
From 7.2.0 to 7.2.11
From 7.4.0 to 7.4.10
From 7.6.0 to 7.6.6
From 7.6.3 to 7.6.6
Fortinet
From 7.0.0 to 7.0.18
From 7.2.0 to 7.2.12
From 7.4.0 to 7.4.11
From 7.6.0 to 7.6.6
Fortinet
From 7.0.0 to 7.0.22
From 7.2.0 to 7.2.15
From 7.4.0 to 7.4.12
From 7.6.0 to 7.6.4
Fortinet
From 7.4.0 to 7.4.11
From 7.6.0 to 7.6.6
From 8.0.0 to 8.0.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Ruggedcom Ape1808
All versions

References (4)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
MitigationVendor Advisory

Timeline

No history available yet.