- Description
- A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortimanager, fortimanager_cloud
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@fortinet.com
- CWE-288
- Hype score
- Not currently trending
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/40UzccobEM
@aMI_KUH95291
16 Aug 2026
122 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468)https://t.co/v2LGpBaCpz "FortiWebやFortiManagerはネットワーク境界やセキュリティ機器の管理に
@catnap707
16 Aug 2026
247 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/zzkbT14v53 #セキュリティ対策Lab #security #securitynews #脆弱性
@securityLab_jp
16 Aug 2026
158 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Fortinet has patched multiple critical authentication flaws across FortiWeb, FortiManager & FortiClient. 1. CVE-2026-26035 (FortiWeb): Improper RADIUS wildcard auth lets attackers log in with random creds. 2. CVE-2026-70468 (FortiManager): Auth bypass in FGFM protocol
@techepages
13 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "88F5C2ED-4F65-4579-8227-29FB64422C42",
"versionEndExcluding": "7.2.10",
"versionStartIncluding": "7.2.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0E642AB7-A2B0-4E38-9C34-B918F041D4D3",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager:7.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "E4EB37D1-158E-4C19-966E-328980CF5DC6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6F00D039-7104-446D-BB6D-F8A9E90FD8D4",
"versionEndExcluding": "7.2.10",
"versionStartIncluding": "7.2.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EFEA33E6-7AAD-4C5B-BA4C-8D783526EF87",
"versionEndIncluding": "7.4.6",
"versionStartIncluding": "7.4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimanager_cloud:7.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "F144EF3A-25C4-4AAF-B45B-985C6E1A6A7A",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]