CVE-2026-70468: FGFM Authentication Weakening via CLI Configuration
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
Other sources
An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
Fortinet FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.6 - Upgrade
Upgrade
Fortinet FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
Fortinet FortiManagerto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
Fortinet FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.6 - Upgrade
Upgrade
Fortinet FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70468?
The severity of CVE-2026-70468 is high with a CVSS score of 7.3.
How does CVE-2026-70468 affect Fortinet FortiManager?
CVE-2026-70468 allows authentication bypass using an alternate path or channel in Fortinet FortiManager and FortiManager Cloud.
Which versions of Fortinet FortiManager are affected by CVE-2026-70468?
CVE-2026-70468 affects FortiManager versions 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9.
What are the potential impacts of CVE-2026-70468?
An attacker exploiting CVE-2026-70468 could gain unauthorized access to the FortiManager systems.
How do I fix CVE-2026-70468?
To fix CVE-2026-70468, it is recommended to update to the latest patched versions of FortiManager and FortiManager Cloud.