CVE-2026-24858: critical vulnerability in Fortinet FortiAnalyzer
Published · Updated
80Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA.
ssvc Actcvss 9.4epss 86%
from disclosure to weapon
Published on NVDJan 27
CISA KEVJan 27
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2026-01-30
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
In short
A flaw in Fortinet products allows attackers with a FortiCloud account to log into other users' devices if FortiCloud SSO is enabled. This bypasses normal authentication and gives unauthorized access to sensitive systems.
Technical detail
Authentication bypass via alternate channel (CWE-288) affecting multiple Fortinet products when FortiCloud SSO is enabled. An attacker with any valid FortiCloud account and registered device can authenticate as other users on unrelated devices. The vulnerability exploits improper validation of SSO credentials across device boundaries.
Summary generated and translated by AI from the official description.
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.