IM
IronMonkey Threat Research

CVE-2026-24858 CRITICAL

Published: 2026-01-27 | Last Modified: 2026-05-12 | Status: Analyzed

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Additional Descriptions (1)

Una vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo [CWE-288] en Fortinet FortiAnalyzer 7.6.0 hasta 7.6.5, FortiAnalyzer 7.4.0 hasta 7.4.9, FortiAnalyzer 7.2.0 hasta 7.2.11, FortiAnalyzer 7.0.0 hasta 7.0.15, FortiManager 7.6.0 hasta 7.6.5, FortiManager 7.4.0 hasta 7.4.9, FortiManager 7.2.0 hasta 7.2.11, FortiManager 7.0.0 hasta 7.0.15, FortiOS 7.6.0 hasta 7.6.5, FortiOS 7.4.0 hasta 7.4.10, FortiOS 7.2.0 hasta 7.2.12, FortiOS 7.0.0 hasta 7.0.18, FortiProxy 7.6.0 hasta 7.6.4, FortiProxy 7.4.0 hasta 7.4.12, FortiProxy 7.2.0 hasta 7.2.15, FortiProxy 7.0.0 hasta 7.0.22, FortiWeb 8.0.0 hasta 8.0.3, FortiWeb 7.6.0 hasta 7.6.6, FortiWeb 7.4.0 hasta 7.4.11 puede permitir a un atacante con una cuenta de FortiCloud y un dispositivo registrado iniciar sesión en otros dispositivos registrados en otras cuentas, si la autenticación SSO de FortiCloud está habilitada en esos dispositivos.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-288

Affected Products

Vendor Product Version Update Type
fortinet fortianalyzer * <built-in method update of dict object at 0x7b067df80480> Application
fortinet fortianalyzer * <built-in method update of dict object at 0x7b06bedb6980> Application
fortinet fortianalyzer * <built-in method update of dict object at 0x7b06e9475580> Application
fortinet fortianalyzer * <built-in method update of dict object at 0x7b067c1abd80> Application
fortinet fortimanager * <built-in method update of dict object at 0x7b070bf18bc0> Application
fortinet fortimanager * <built-in method update of dict object at 0x7b06fee09280> Application
fortinet fortimanager * <built-in method update of dict object at 0x7b0755d16680> Application
fortinet fortimanager * <built-in method update of dict object at 0x7b067c1a8d80> Application
fortinet fortiproxy * <built-in method update of dict object at 0x7b06fee087c0> Application
fortinet fortiproxy * <built-in method update of dict object at 0x7b06fee0b240> Application
fortinet fortiproxy * <built-in method update of dict object at 0x7b067c1ab1c0> Application
fortinet fortiproxy * <built-in method update of dict object at 0x7b06bedb5f00> Application
fortinet fortiweb * <built-in method update of dict object at 0x7b06e9d51040> Application
fortinet fortiweb * <built-in method update of dict object at 0x7b06bef8c280> Application
fortinet fortiweb * <built-in method update of dict object at 0x7b070b21b780> Application
fortinet fortios * <built-in method update of dict object at 0x7b06bef8ddc0> Operating System
fortinet fortios * <built-in method update of dict object at 0x7b06bedb4d00> Operating System
fortinet fortios * <built-in method update of dict object at 0x7b070b1a3fc0> Operating System
fortinet fortios * <built-in method update of dict object at 0x7b06bedb4ac0> Operating System
siemens ruggedcom_ape1808_firmware - <built-in method update of dict object at 0x7b067c1a9bc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_ape1808_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_ape1808:-:*:*:*:*:*:*:*

References

Notification
Message here