CVE-2026-22153: LDAP authentication bypass in Agentless VPN and FSSO
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22153?
CVE-2026-22153 has a critical severity rating due to the potential for unauthenticated remote access.
How do I fix CVE-2026-22153?
To fix CVE-2026-22153, upgrade FortiOS to version 7.6.5 or later.
What affected software versions are vulnerable to CVE-2026-22153?
FortiOS versions from 7.6.0 to 7.6.4 are vulnerable to CVE-2026-22153.
Can I mitigate CVE-2026-22153 without upgrading?
No effective mitigation techniques are available other than upgrading to a secure version for CVE-2026-22153.
What type of attack does CVE-2026-22153 allow?
CVE-2026-22153 allows an unauthenticated attacker to bypass LDAP authentication in specific configurations.