Junglewise Threat Intelligence

CVE-2026-24858: Fortinet Multiple Products authentication bypass in FortiCloud SSO

CVE-2026-24858 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-01-27

Technologies: Fortinet FortiWeb, Fortinet FortiManager, Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet Fortianalyzer, Fortinet FortiSwitchManager, Apple Multiple Products, Fortinet FortiProxy. Vendors: Fortinet, Siemens, Apple.

Executive brief

A critical vulnerability in several Fortinet networking and security products allows unauthorized users to bypass login security and gain administrative control. This occurs when the FortiCloud Single Sign-On (SSO) feature is enabled, potentially allowing an attacker with their own FortiCloud account to access other organizations' devices. Attackers have been observed using this flaw to download configuration files and create backdoors for persistent access.

Technical details

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] exists in the FortiCloud SSO implementation across multiple Fortinet product lines. The flaw allows an attacker who possesses a valid FortiCloud account and a registered device to authenticate as an administrator on other devices registered to different accounts, provided FortiCloud SSO is enabled. Exploitation does not require prior authentication to the target device. In the wild, attackers have been observed creating local administrative accounts and exfiltrating configuration files. Fortinet has since implemented server-side restrictions on FortiCloud to block vulnerable versions, but local firmware updates are required for full remediation.

Affected products

  • Fortinet FortiAnalyzer 7.6.0 through 7.6.5, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.15
  • Fortinet FortiManager 7.6.0 through 7.6.5, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.15
  • Fortinet FortiOS 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.12, 7.0.0 through 7.0.18
  • Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4.0 through 7.4.12, 7.2.0 through 7.2.15, 7.0.0 through 7.0.22
  • Fortinet FortiWeb 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11
  • Fortinet FortiNAC-F 7.6.3 through 7.6.5
  • Fortinet FortiSwitchManager 7.2.0 through 7.2.8, 7.0.0 through 7.0.7
  • Siemens RUGGEDCOM APE1808 (Fortigate NGFW) All versions with Fortinet NGFW < V7.4.11

Timeline

  • 2026-01-22: other: Malicious FortiCloud accounts used in exploitation were locked out by Fortinet.
  • 2026-01-26: other: Fortinet temporarily disabled FortiCloud SSO globally to protect customers.
  • 2026-01-27: disclosed: Initial advisory publication.
  • 2026-01-27: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog.
  • 2026-01-27: patched: FortiCloud SSO re-enabled with enforcement to block vulnerable firmware versions.

References

Related threats