Executive brief
FortiOS SSL VPN allows remote users to authenticate using SAML, a federated authentication standard. This vulnerability fails to properly expire user sessions, allowing an attacker who obtains a SAML authentication record (for example, from a former admin whose account was removed) to reuse that record to regain access to the VPN. This could provide unauthorized access to corporate networks and sensitive resources.
Technical details
An insufficient session expiration vulnerability (CWE-613) exists in the FortiOS SSL VPN SAML authentication handler. The vulnerability allows reuse of SAML records to re-open terminated user sessions. The attack requires possession of a valid SAML record from a previous session, but does not require valid current credentials; an unauthenticated attacker with access to a SAML record can bypass the session termination mechanism. Affected versions include FortiOS 6.4 (all versions), 7.0.0–7.0.16, 7.2.0–7.2.10, 7.4.0–7.4.6, and 7.6.0–7.6.2. Patches are available; users can also mitigate by disabling the "Use external browser as user-agent for saml user authentication" option and using the FortiClient built-in browser instead.
Affected products
- Fortinet FortiOS 6.4 all versions, 7.0.0 through 7.0.16, 7.2.0 through 7.2.10, 7.4.0 through 7.4.6, 7.6.0 through 7.6.2
Timeline
- 2025-10-14: disclosed