CVE-2026-24858 is a critical authentication bypass vulnerability (CWE-288) affecting multiple Fortinet products, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. This flaw allows an attacker with a FortiCloud account and a registered device to gain unauthorized access to other devices registered to different accounts if FortiCloud SSO authentication is enabled. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a network-based attack vector, low attack complexity, and can lead to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and extensive media coverage, despite no public exploit code being readily available through common channels like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, <= 7.0.15CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.11CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.10CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.6.0, < 7.6.6CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.15CPE matchmatch criteria | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.