CVE-2026-24858

CRITICAL(9.8)KEVLikely Exploited

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Description

CVE-2026-24858 is a critical authentication bypass vulnerability affecting multiple Fortinet products including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. With a CVSS v3.1 base score of 9.8, the flaw exploits an alternate path or channel to bypass authentication, allowing an unauthenticated remote attacker to gain unauthorized access to affected systems. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of January 30, 2026, and the ransomware association is currently classified as unknown. The EPSS score of 2.42% at the 84.9th percentile indicates above-average exploitation activity, and the breadth of affected Fortinet products across network security, analytics, and management infrastructure makes this vulnerability an extremely high-priority remediation target for any organization running Fortinet solutions.

KEV Information

Vendor
Fortinet
Product
Multiple Products
Date Added
January 27, 2026
Due Date
January 30, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
fortinetfortianalyzer>= 7.0.0, <= 7.0.15; >= 7.2.0, <= 7.2.11; >= 7.4.0, < 7.4.10; >= 7.6.0, < 7.6.6
fortinetfortimanager>= 7.0.0, <= 7.0.15; >= 7.2.0, <= 7.2.11; >= 7.4.0, < 7.4.10; >= 7.6.0, < 7.6.6
fortinetfortinac-f>= 7.6.3, < 7.6.6
fortinetfortiproxy>= 7.0.0, <= 7.0.22; >= 7.2.0, <= 7.2.15; >= 7.4.0, <= 7.4.12; >= 7.6.0, <= 7.6.4
fortinetfortiweb>= 7.4.0, <= 7.4.11; >= 7.6.0, <= 7.6.6; >= 8.0.0, <= 8.0.3
fortinetfortios>= 7.0.0, <= 7.0.18; >= 7.2.0, <= 7.2.12; >= 7.4.0, < 7.4.11; >= 7.6.0, < 7.6.6
siemensruggedcom ape1808 firmware-

References

Weakness Type

CWE-288: Authentication Bypass Using an Alternate Path or Channel

CVE-2026-24858 is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). This weakness occurs when a system that requires authentication can be accessed through an alternative path or communication channel that does not enforce the same authentication requirements. In the affected Fortinet products, the authentication mechanism on the primary access path can be circumvented by accessing the system through an alternate path that was not properly protected with equivalent authentication controls. This allows an attacker to reach authenticated functionality without providing valid credentials. CWE-288 is distinct from simple credential bypass because the attacker does not exploit a flaw in the authentication logic itself but rather discovers a different route to the protected resources that lacks authentication enforcement. In network security infrastructure like firewalls and management platforms, this class of vulnerability is especially severe because these systems are trusted components that protect the rest of the network. Learn more about CWE-288

Impact Analysis

The impact of CVE-2026-24858 is exceptionally severe due to the breadth and criticality of the affected product line. Confidentiality is completely compromised across all affected products. In FortiAnalyzer and FortiManager, the attacker gains access to security logs, event data, network analytics, configuration data for all managed Fortinet devices, and potentially stored credentials. In FortiOS (FortiGate firewalls), the attacker can read firewall rules, VPN configurations, user databases, SSL certificates, and all traffic inspection data. In FortiProxy, the attacker accesses web filtering policies, proxy configurations, and potentially cached content. In FortiWeb, the attacker can view web application firewall rules, protected application configurations, and security policies.

Integrity suffers maximum impact as an attacker with unauthorized access to Fortinet management infrastructure can modify firewall rules to allow malicious traffic, alter security policies to create blind spots, reconfigure VPN settings to intercept traffic, push malicious configurations to managed devices through FortiManager, and manipulate security analytics in FortiAnalyzer to hide attack evidence.

Availability faces critical risk because the attacker can disrupt network security operations by modifying or deleting firewall rules, disrupting VPN connectivity, disabling security inspection, or rendering management platforms inoperable. Fortinet's advisory references SSO abuse analysis, suggesting the authentication bypass involves the Single Sign-On mechanism. The EPSS score of 2.42% at the 84.9th percentile combined with the KEV listing and the massive attack surface across multiple product lines makes this one of the highest-priority remediation targets in the current threat landscape. The affected version ranges span FortiAnalyzer 7.0-7.6, FortiManager 7.0-7.6, FortiOS 7.0-7.6, FortiProxy 7.0-7.6, and FortiWeb 7.4-8.0.

Exploit Maturity

CVE-2026-24858 has confirmed active exploitation as evidenced by its inclusion in CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of January 30, 2026. The EPSS score of 2.42% at the 84.9th percentile reflects exploitation activity that exceeds the majority of tracked vulnerabilities. The official Fortinet advisory is available at FG-IR-26-060, and Fortinet has published a detailed analysis of the exploitation mechanism at their PSIRT blog on SSO abuse on FortiOS.

Fortinet products are among the most frequently targeted network security appliances by both state-sponsored and criminal threat actors. The company's firewall and management products protect critical network boundaries, making them high-value targets where a single compromise can provide access to an entire organization's network. The authentication bypass through an alternate path means that standard login monitoring will not detect the attacker's access, as they circumvent the normal authentication flow entirely. The broad range of affected products (FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb) means that organizations running any combination of these Fortinet solutions face a wide attack surface. The ransomware association is unknown, but Fortinet appliance compromises have historically been used as initial access vectors for both espionage and ransomware campaigns.

Remediation

  1. Apply Fortinet security updates immediately across all affected products. Upgrade FortiAnalyzer and FortiManager to version 7.4.10 or 7.6.6 or later. Upgrade FortiOS to version 7.4.11 or 7.6.6 or later. Upgrade FortiProxy to a patched version beyond the affected ranges. Upgrade FortiWeb to a patched version beyond the affected ranges. Consult the Fortinet PSIRT advisory FG-IR-26-060 for exact version numbers and upgrade paths for each product.

  2. Review and restrict SSO configurations as an immediate compensating control. Fortinet's published analysis on SSO abuse indicates the authentication bypass involves SSO mechanisms. Disable SSO on affected systems if it is not a business requirement, and restrict SSO trust relationships to only verified and necessary identity providers. Review SSO configurations for any unauthorized modifications.

  3. Restrict management interface access for all affected Fortinet products. Ensure that FortiAnalyzer, FortiManager, and the management interfaces of FortiOS, FortiProxy, and FortiWeb are only accessible from dedicated management networks and not reachable from the internet or untrusted network segments. Implement out-of-band management networks where possible to isolate management traffic from production traffic.

  4. Conduct forensic analysis of all affected Fortinet appliances by reviewing authentication logs for unauthorized access patterns, checking for configuration changes that were not authorized through change management processes, examining admin account lists for unauthorized accounts, and reviewing firewall rules and security policies for unexpected modifications. Pay particular attention to SSO-related authentication events that bypass normal login workflows.

  5. Rotate administrative credentials and certificates for all affected Fortinet devices after patching. This includes local admin passwords, API keys, SSL certificates, VPN pre-shared keys, and any credentials used for integration with LDAP, RADIUS, TACACS+, or other authentication systems. Also review and reissue any certificates managed by FortiManager that may have been exposed.

Technical Details

CVE-2026-24858 is an authentication bypass vulnerability affecting multiple Fortinet products, characterized by the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. All vector components reflect maximum exploitability: Attack Vector (AV:N) confirms remote network exploitation. Attack Complexity (AC:L) means the bypass works reliably. Privileges Required (PR:N) indicates no authentication is needed, which is the core issue. User Interaction (UI:N) confirms fully automated exploitation. Scope (S:U) keeps impact within the affected product's context, but these are network security infrastructure components with broad system access.

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), and Fortinet's published blog on SSO abuse suggests the bypass involves the Single Sign-On authentication pathway. Fortinet products support various SSO mechanisms including SAML, OAuth, and proprietary SSO agents for transparent user authentication. The vulnerability likely exists in how the SSO authentication path validates or trusts authentication assertions, allowing an attacker to craft requests that are processed through the SSO channel without proper verification of the authentication token's validity, issuer, or signature.

The affected version ranges are extensive: FortiAnalyzer 7.0.0 through 7.0.15, 7.2.0 through 7.2.11, 7.4.0 through versions before 7.4.10, and 7.6.0 through versions before 7.6.6. FortiManager follows identical version ranges. FortiOS affects 7.0.0 through 7.0.18, 7.2.0 through 7.2.12, 7.4.0 through versions before 7.4.11, and 7.6.0 through versions before 7.6.6. FortiProxy affects 7.0.0 through 7.0.22, 7.2.0 through 7.2.15, 7.4.0 through 7.4.12, and 7.6.0 through 7.6.4. FortiWeb affects 7.4.0 through 7.4.11, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.3. The shared SSO implementation across these products explains why a single vulnerability class affects such a broad product portfolio. The patch addresses the authentication validation in the SSO path to ensure that all authentication assertions are properly verified regardless of the access channel used.

Frequently Asked Questions

What is CVE-2026-24858?

CVE-2026-24858 is a critical authentication bypass vulnerability affecting multiple Fortinet products including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. It allows unauthenticated remote attackers to bypass authentication through an alternate path, with a CVSS score of 9.8.

Which Fortinet products are affected?

The vulnerability affects FortiAnalyzer 7.0-7.6, FortiManager 7.0-7.6, FortiOS 7.0-7.6, FortiProxy 7.0-7.6, and FortiWeb 7.4-8.0. Each product has specific affected version ranges detailed in the Fortinet PSIRT advisory FG-IR-26-060.

How does the authentication bypass work?

Fortinet's analysis points to SSO (Single Sign-On) abuse as the mechanism. The attacker bypasses the normal authentication flow by accessing the system through an alternate authentication channel that does not properly validate credentials, gaining unauthorized access without legitimate SSO tokens.

Should I patch all Fortinet products or just the internet-facing ones?

All affected Fortinet products should be patched regardless of their network exposure. While internet-facing systems are at highest immediate risk, internal FortiAnalyzer, FortiManager, and FortiWeb instances can be targeted by attackers who have gained initial access to the internal network through other means. The broad product scope means a comprehensive patching approach is required.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score85.84%
EPSS Percentile99.7%

Dates

PublishedJanuary 27, 2026
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.