CVE-2026-24858
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 29 Days)
Authentication Bypass Using an Alternate Path or Channel
IncompleteCommon Consequences
Applicable Platforms
Fortios by Fortinet
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Fortios by Fortinet
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Fortiproxy by Fortinet
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortiproxy by Fortinet
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Fortiweb by Fortinet
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortios by Fortinet
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Fortios by Fortinet
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Fortiproxy by Fortinet
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Fortiweb by Fortinet
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortiproxy by Fortinet
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Fortiweb by Fortinet
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*