PT-2026-24239 · Fortinet · Fortianalyzer+2

CVE-2026-22572

·

Publicado

2026-03-10

·

Atualizado

2026-03-18

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer versions 7.2.2 through 7.6.3 Fortinet FortiManager versions 7.2.2 through 7.6.3 Fortinet FortiManager Cloud versions 7.2.2 through 7.6.3
Description This issue is an authentication bypass that uses an alternate path or channel. An attacker with knowledge of the administrator's password may be able to bypass multifactor authentication checks by submitting multiple crafted requests. The vulnerability affects Fortinet FortiAnalyzer and FortiManager products.
Recommendations FortiAnalyzer versions 7.2.2 through 7.6.3 should be updated. FortiManager versions 7.2.2 through 7.6.3 should be updated. FortiManager Cloud versions 7.2.2 through 7.6.3 should be updated.

Correção

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-03209
CVE-2026-22572

Produtos afetados

Fortianalyzer
Fortimanager
Fortimanager Cloud