FG-IR-26-079: Authentication Lockout Bypass via Race Condition
Published Mar 10, 2026
·Updated
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiManager and FortiAnalyzer may allow an attacker to bypass bruteforce protections via exploitation of race conditions.
Affected Software
20 affected componentsFixes available
Fortinet FortiAnalyzer>=7.6.0<=7.6.4
Fortinet FortiAnalyzer>=7.4
Fortinet FortiAnalyzer>=7.2
Fortinet FortiAnalyzer>=7.0
Fortinet FortiAnalyzer>=6.4
Fortinet FortiAnalyzer Cloud>=7.6.0<=7.6.4
Fortinet FortiAnalyzer Cloud>=7.4
Fortinet FortiAnalyzer Cloud>=7.2
Fortinet FortiAnalyzer Cloud>=7.0
Fortinet FortiAnalyzer Cloud>=6.4
Fortinet FortiManager>=7.6.0<=7.6.4
Fortinet FortiManager>=7.4
Fortinet FortiManager>=7.2
Fortinet FortiManager>=7.0
Fortinet FortiManager>=6.4
Fortinet FortiManager Cloud>=7.6.0<=7.6.4
Fortinet FortiManager Cloud>=7.4
Fortinet FortiManager Cloud>=7.2
Fortinet FortiManager Cloud>=7.0
Fortinet FortiManager Cloud>=6.4
Event History
Mar 10, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-079?
The severity of FG-IR-26-079 is considered critical as it allows an attacker to bypass brute-force protections.
2
How do I fix FG-IR-26-079?
To fix FG-IR-26-079, upgrade FortiManager or FortiAnalyzer to version 7.6.5 or later.
3
Which products are affected by FG-IR-26-079?
FG-IR-26-079 affects FortiManager and FortiAnalyzer versions below 7.6.5, including various versions of FortiManager Cloud.
4
What type of vulnerability is FG-IR-26-079?
FG-IR-26-079 is categorized as an authentication lockout bypass vulnerability due to race conditions.
5
Can FG-IR-26-079 be exploited remotely?
Yes, FG-IR-26-079 can potentially be exploited remotely, allowing attackers to bypass authentication safeguards.