CVE-2025-59719: Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Other sources
An Improper Verification of Cryptographic Signature vulnerability[CWE-347] in FortiOS, FortiWeb, FortiProxy and FortiSwitchManager mayallow an unauthenticated attacker to bypass the FortiCloud SSO loginauthentication via a crafted SAML message, if that feature is enabled on the device. Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch "Allow administrative login using FortiCloud SSO" in the registration page, FortiCloud SSO login is enabled upon registration. To prevent being affected by this vulnerability on vulnerableversions, please turn off the FortiCloud login feature (if enabled) temporarily untilupgrading to a non-affected version.To turn off FortiCloud login, go to System -> Settings -> Switch"Allow administrative login using FortiCloud SSO" to Off. Or type thefollowing command in the CLI: config system global set admin-forticloud-sso-login disableend
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.18 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.8.0 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.22 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.15 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.11 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.4.10 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 8.0.1 - Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 25.3.b - Configuration
To prevent being affected by the FortiCloud SSO login authentication bypass vulnerability in vulnerable versions, turn off the FortiCloud login feature (if enabled) by setting “Allow administrative login using FortiCloud SSO” to Off at System -> Settings -> Switch.
Fortinet FortiOS (System Settings) Allow administrative login using FortiCloud SSO = Off - Configuration
Alternatively, disable the FortiCloud SSO login feature via CLI: config system global set admin-forticloud-sso-login disable.
Fortinet FortiOS (CLI) admin-forticloud-sso-login = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59719?
The severity of CVE-2025-59719 has not been explicitly rated, but it involves an improper verification of cryptographic signatures, which can lead to serious security issues.
How do I fix CVE-2025-59719?
To fix CVE-2025-59719, update affected FortiOS, FortiProxy, FortiWeb, or FortiSwitchManager to the latest patched version as specified by Fortinet.
Which Fortinet products are affected by CVE-2025-59719?
CVE-2025-59719 affects FortiOS, FortiProxy, FortiWeb, and FortiSwitchManager versions specified within certain ranges.
Can CVE-2025-59719 be exploited remotely?
Yes, an unauthenticated attacker can exploit CVE-2025-59719 remotely through a crafted SAML message.
What does CVE-2025-59719 allow an attacker to do?
CVE-2025-59719 allows an attacker to bypass FortiCloud SSO login authentication when the feature is enabled on the affected devices.