CVE-2026-23708
published 2026-04-14CVE-2026-23708: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through…
PriorityP359high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.28%
20.5th percentile
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | >= 7.5.0 < 7.5.3 | 7.5.3 |
| fortinet | fortisoar | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortisoar_on-premise | 7.5.0 – 7.5.2 | — |
| fortinet | fortisoar_on-premise | 7.6.0 – 7.6.3 | — |
| fortinet | fortisoar_paas | 7.5.0 – 7.5.2 | — |
| fortinet | fortisoar_paas | 7.6.0 – 7.6.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
2FA request can be replayed without a valid token after one successful request
vendor_fortinet·2026-04-14·CVSS 7.5
CVE-2026-23708 [HIGH] CWE-287 2FA request can be replayed without a valid token after one successful request
FG-IR-26-101: 2FA request can be replayed without a valid token after one successful request
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.
CVEs: CVE-2026-23708
CWEs: CWE-287
CVSS: 7.5 (high)
Affected products: FortiSOAR, Fortinet
GHSA
GHSA-6p3p-h3vc-6rh5: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7
ghsa_unreviewed·2026-04-14
CVE-2026-23708 [HIGH] CWE-287 GHSA-6p3p-h3vc-6rh5: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published