FG-IR-26-090: MFA Bypass in GUI
An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiManager and FortiAnalyzer multifactor authentication may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-090?
The severity of FG-IR-26-090 is critical due to the potential for unauthorized access via multifactor authentication bypass.
How do I fix FG-IR-26-090?
To fix FG-IR-26-090, upgrade FortiAnalyzer and FortiManager to version 7.6.4 or 7.4.8 as appropriate based on your current version.
Which versions are affected by FG-IR-26-090?
FG-IR-26-090 affects FortiAnalyzer and FortiManager versions 7.6.0 through 7.6.3 and 7.4.0 through 7.4.7, among others.
What products are vulnerable to FG-IR-26-090?
FG-IR-26-090 impacts Fortinet products including FortiAnalyzer, FortiManager, and their cloud counterparts.
Can FG-IR-26-090 be exploited remotely?
Yes, FG-IR-26-090 can potentially be exploited remotely if an attacker possesses the administrator's password.