Junglewise Threat Intelligence

CVE-2025-59719: Fortinet Multiple Products FortiCloud SSO auth bypass via SAML signature flaw

CVE-2025-59719 · Severity: critical · CVSS 9.8 · Published 2025-12-09

Technologies: Fortinet FortiWeb, Fortinet FortiOS, Fortinet FortiSwitchManager, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A vulnerability in several Fortinet networking and security products could allow an unauthorized person to bypass login protections and gain administrative access. This occurs when the FortiCloud Single Sign-On (SSO) feature is enabled, allowing an attacker to spoof a login response. If exploited, an attacker could take full control of the device, potentially leading to data theft, network disruption, or further attacks on the corporate environment.

Technical details

An improper verification of cryptographic signature vulnerability (CWE-347) exists in the GUI component of FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. The flaw allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted SAML response message to the FortiCloud SSO login endpoint. This vulnerability is only exploitable if the 'Allow administrative login using FortiCloud SSO' feature is enabled, which is often toggled on during device registration to FortiCare. Successful exploitation grants the attacker administrative access to the device management interface. Patches are available for all affected product lines, and a workaround exists to disable the FortiCloud SSO login feature via the CLI or GUI.

Affected products

  • Fortinet FortiWeb 8.0.0, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9
  • Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17
  • Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4.0 through 7.4.10, 7.2.0 through 7.2.14, 7.0.0 through 7.0.21
  • Fortinet FortiSwitchManager 7.2.0 through 7.2.6, 7.0.0 through 7.0.5

Timeline

  • 2025-12-09: disclosed: Initial publication by Fortinet
  • 2025-12-09: advisory: Fortinet PSIRT FG-IR-25-647 published

References

Related threats