CVE-2026-24858: Administrative FortiCloud SSO authentication bypass

Published Jan 27, 2026
·
Updated

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiSwitchManager, FortiWeb may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch "Allow administrative login using FortiCloud SSO" in the registration page, FortiCloud SSO login is enabled upon registration. This vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, which were locked out on 2026-01-22. In order to protect its customers from further exploit, Fortinet disabled FortiCloud SSO on FortiCloud side on 2026-01-26. It was re-enabled on 2026-01-27 and no longer supports login from devices running vulnerable versions. Consequently, customers must upgrade to the latest versions listed below for the FortiCloud SSO authentication to function.FortiManager Cloud, FortiAnalyzer Cloud, FortiGate Cloud are NOT impacted.Setups with Custom IdP for SSO instead of FortiCloud are not impacted (including setups using FortiAuthenticator as the Custom IdP)

Other sources

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

MITRE

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CISA

Affected Software

44 affected componentsFixes available
Fortinet Multiple Products
Fortinet FortiAnalyzer>=7.6.0<=7.6.5
Fortinet FortiAnalyzer>=7.4.0<=7.4.9
Fortinet FortiAnalyzer>=7.2.0<=7.2.11
Fortinet FortiAnalyzer>=7.0.0<=7.0.15
Fortinet FortiManager>=7.6.0<=7.6.5
Fortinet FortiManager>=7.4.0<=7.4.9
Fortinet FortiManager>=7.2.0<=7.2.11
Fortinet FortiManager>=7.0.0<=7.0.15
Fortinet FortiOS>=7.6.0<=7.6.5
Fortinet FortiOS>=7.4.0<=7.4.10
Fortinet FortiOS>=7.2.0<=7.2.12
Fortinet FortiOS>=7.0.0<=7.0.18
Fortinet FortiProxy>=7.6.0<=7.6.4
Fortinet FortiProxy>=7.4.0<=7.4.12
Fortinet FortiProxy>=7.2.0<=7.2.15
Fortinet FortiProxy>=7.0.0<=7.0.22
Fortinet FortiSwitchManager>=7.2.0<=7.2.8
Fortinet FortiSwitchManager>=7.0.0<=7.0.7
Fortinet FortiWeb>=8.0.0<=8.0.3
Fortinet FortiWeb>=7.6.0<=7.6.6
Fortinet FortiWeb>=7.4.0<=7.4.11
Fortinet FortiAnalyzer>=7.0.0<=7.0.15
Fortinet FortiAnalyzer>=7.2.0<=7.2.11
Fortinet FortiAnalyzer>=7.4.0<7.4.10
Fortinet FortiAnalyzer>=7.6.0<7.6.6
Fortinet FortiManager>=7.0.0<=7.0.15
Fortinet FortiManager>=7.2.0<=7.2.11
Fortinet FortiManager>=7.4.0<7.4.10
Fortinet FortiManager>=7.6.0<7.6.6
Fortinet FortiProxy>=7.0.0<=7.0.22
Fortinet FortiProxy>=7.2.0<=7.2.15
Fortinet FortiProxy>=7.4.0<=7.4.12
Fortinet FortiProxy>=7.6.0<=7.6.4
Fortinet FortiWeb>=7.4.0<=7.4.11
Fortinet FortiWeb>=7.6.0<=7.6.6
Fortinet FortiWeb>=8.0.0<=8.0.3
Fortinet FortiOS>=7.0.0<=7.0.18
Fortinet FortiOS>=7.2.0<=7.2.12
Fortinet FortiOS>=7.4.0<7.4.11
Fortinet FortiOS>=7.6.0<7.6.6
All of the following
Siemens Ruggedcom Ape1808 Firmware
Siemens Ruggedcom Ape1808
Fortinet FortiNAC-F>=7.6.3<7.6.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 8.0.0
  2. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.6.6
  3. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.4.11
  4. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.2.13
  5. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.0.19
  6. Upgrade

    Upgrade FortiManager to a version that resolves this vulnerability.

    Fixed in 8.0.0
  7. Upgrade

    Upgrade FortiManager to a version that resolves this vulnerability.

    Fixed in 7.6.6
  8. Upgrade

    Upgrade FortiManager to a version that resolves this vulnerability.

    Fixed in 7.4.10
  9. Upgrade

    Upgrade FortiManager to a version that resolves this vulnerability.

    Fixed in 7.2.12
  10. Upgrade

    Upgrade FortiManager to a version that resolves this vulnerability.

    Fixed in 7.0.16
  11. Upgrade

    Upgrade FortiAnalyzer to a version that resolves this vulnerability.

    Fixed in 7.6.6
  12. Upgrade

    Upgrade FortiAnalyzer to a version that resolves this vulnerability.

    Fixed in 7.4.10
  13. Upgrade

    Upgrade FortiAnalyzer to a version that resolves this vulnerability.

    Fixed in 7.2.12
  14. Upgrade

    Upgrade FortiAnalyzer to a version that resolves this vulnerability.

    Fixed in 7.0.16
  15. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.6.5
  16. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.4.13
  17. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.2.16
  18. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.0.23
  19. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 8.0.4
  20. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 7.6.7
  21. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 7.4.12
  22. Upgrade

    Upgrade FortiNAC-F to a version that resolves this vulnerability.

    Fixed in 7.6.6
  23. Upgrade

    Upgrade FortiSwitchManager to a version that resolves this vulnerability.

    Fixed in 7.2.9
  24. Upgrade

    Upgrade FortiSwitchManager to a version that resolves this vulnerability.

    Fixed in 7.0.8
  25. Remove

    Remove Fortinet affected product(s) from your environment.

    Discontinue use of the product if vendor mitigations are unavailable.

  26. Configuration

    Disable the 'Allow administrative login using FortiCloud SSO' toggle on the device registration page to prevent FortiCloud SSO administrative logins.

    FortiCloud SSO (device registration GUI) Allow administrative login using FortiCloud SSO = false
  27. Compensating control

    Apply mitigations per Fortinet vendor instructions and follow applicable BOD 22-01 guidance for cloud services; if vendor mitigations are available, implement them immediately.

Event History

Jan 27, 2026
Advisory Published
via FortiGuard·12:00 AM
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·11:19 PM
News Published
via BleepingComputer·11:21 PM
Jan 28, 2026
News Published
via The Register·04:30 PM
News Published
via The Register·04:34 PM
Mar 30, 2026
News Published
via BleepingComputer·07:48 AM
Apr 6, 2026
News Published
via BleepingComputer·04:02 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-24858?

CVE-2026-24858 is rated as a high severity vulnerability due to its potential for unauthorized authentication access.

2

How do I fix CVE-2026-24858?

To mitigate CVE-2026-24858, ensure that your FortiOS, FortiManager, and FortiAnalyzer are updated to the latest patched versions.

3

Who is affected by CVE-2026-24858?

CVE-2026-24858 affects users of FortiOS, FortiManager, FortiAnalyzer, and FortiProxy versions within specified vulnerable ranges.

4

What type of vulnerability is CVE-2026-24858?

CVE-2026-24858 is classified as an Authentication Bypass vulnerability, allowing attackers to bypass security controls using a FortiCloud account.

5

What are the potential consequences of CVE-2026-24858?

Exploitation of CVE-2026-24858 could lead to unauthorized access to devices registered under different accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203