cbcvebase.
CVE-2026-24858
published 2026-01-27

CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2026-01-30
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer7.0.0 – 7.0.15
fortinetfortianalyzer7.2.0 – 7.2.11
fortinetfortianalyzer>= 7.4.0 < 7.4.107.4.10
fortinetfortianalyzer7.4.0 – 7.4.9
fortinetfortianalyzer>= 7.6.0 < 7.6.67.6.6
fortinetfortianalyzer7.6.0 – 7.6.5
fortinetforticloud
fortinetfortimanager
fortinetfortimanager7.0.0 – 7.0.15
fortinetfortimanager7.2.0 – 7.2.11
fortinetfortimanager>= 7.4.0 < 7.4.107.4.10
fortinetfortimanager7.4.0 – 7.4.9
fortinetfortimanager>= 7.6.0 < 7.6.67.6.6
fortinetfortimanager7.6.0 – 7.6.5
fortinetfortinet
fortinetfortios
fortinetfortios7.0.0 – 7.0.18
fortinetfortios7.2.0 – 7.2.12
fortinetfortios>= 7.4.0 < 7.4.117.4.11
fortinetfortios7.4.0 – 7.4.10
fortinetfortios>= 7.6.0 < 7.6.67.6.6
fortinetfortios7.6.0 – 7.6.5
fortinetfortiproxy
fortinetfortiproxy7.0.0 – 7.0.22

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL