CVE-2026-24858

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/01/2026
Last modified:
29/01/2026

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.15 (including)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.11 (including)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.10 (excluding)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.6 (excluding)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.15 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.11 (including)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.10 (excluding)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.6 (excluding)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.22 (including)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.15 (including)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.12 (including)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.4 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.11 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.6 (including)
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.3 (including)