FG-IR-26-078: Lack of TLS Certificate Validation during initial SSO Authentication
Published Mar 10, 2026
·Updated
An improper certificate validation [CWE-295] vulnerability in the FortiManager GUI may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
Affected Software
10 affected componentsFixes available
Fortinet FortiAnalyzer>=7.6.0<=7.6.4
Fortinet FortiAnalyzer>=7.4.0<=7.4.8
Fortinet FortiAnalyzer>=7.2
Fortinet FortiAnalyzer>=7.0
Fortinet FortiAnalyzer>=6.4
Fortinet FortiManager>=7.6.0<=7.6.4
Fortinet FortiManager>=7.4.0<=7.4.8
Fortinet FortiManager>=7.2
Fortinet FortiManager>=7.0
Fortinet FortiManager>=6.4
Event History
Mar 10, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-078?
The severity of FG-IR-26-078 is considered high due to the potential for unauthorized access to confidential information.
2
How do I fix FG-IR-26-078?
To fix FG-IR-26-078, upgrade to FortiManager version 7.6.5 or 7.4.9, or apply recommended patches.
3
What impact does FG-IR-26-078 have on FortiManager?
FG-IR-26-078 allows remote unauthenticated attackers to potentially view confidential information via a man-in-the-middle attack.
4
Which FortiManager versions are affected by FG-IR-26-078?
Affected versions of FortiManager include 7.6.0 to 7.6.4 and 7.4.0 to 7.4.8.
5
Is there a workaround for FG-IR-26-078 if I can't update immediately?
Currently, no workarounds are suggested for FG-IR-26-078; upgrading to a secure version is strongly recommended.