PT-2026-5008 · Fortinet · Fortimanager+2
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiAnalyzer versions 7.0.0 through 7.0.15
FortiAnalyzer versions 7.2.0 through 7.2.11
FortiAnalyzer versions 7.4.0 through 7.4.9
FortiAnalyzer versions 7.6.0 through 7.6.5
FortiManager versions 7.0.0 through 7.0.15
FortiManager versions 7.2.0 through 7.2.11
FortiManager versions 7.4.0 through 7.4.9
FortiManager versions 7.6.0 through 7.6.5
FortiNAC-F versions 7.6.3 through 7.6.5
FortiOS versions 7.0.0 through 7.0.18
FortiOS versions 7.2.0 through 7.2.12
FortiOS versions 7.4.0 through 7.4.10
FortiOS versions 7.6.0 through 7.6.5
FortiProxy versions 7.0.0 through 7.0.22
FortiProxy versions 7.2.0 through 7.2.15
FortiProxy versions 7.4.0 through 7.4.12
FortiProxy versions 7.6.0 through 7.6.4
FortiWeb versions 7.4.0 through 7.4.11
FortiWeb versions 7.6.0 through 7.6.6
FortiWeb versions 8.0.0 through 8.0.3
Description
An authentication bypass flaw exists in the FortiCloud single sign-on (SSO) system. This issue allows an attacker possessing a FortiCloud account and a registered device to gain unauthorized administrative access to other devices registered to different accounts, provided that FortiCloud SSO authentication is enabled on the target devices. This flaw has been actively exploited in a large-scale campaign known as FortiBleed, which targeted between 73,932 and 86,644 unique firewall URLs across 194 countries. The campaign involved state-sponsored actors, including Mustang Panda, who used the bypass to extract configurations, harvest credentials, and perform lateral movement into internal Active Directory domains. The attackers utilized a distributed hash-cracking infrastructure and AI-driven tools to automate penetration testing and credential theft.
Recommendations
For FortiAnalyzer versions 7.0.0 through 7.0.15, 7.2.0 through 7.2.11, 7.4.0 through 7.4.9, and 7.6.0 through 7.6.5, update to a version that fixes the authentication bypass.
For FortiManager versions 7.0.0 through 7.0.15, 7.2.0 through 7.2.11, 7.4.0 through 7.4.9, and 7.6.0 through 7.6.5, update to a version that fixes the authentication bypass.
For FortiNAC-F versions 7.6.3 through 7.6.5, update to a version that fixes the authentication bypass.
For FortiOS versions 7.0.0 through 7.0.18, 7.2.0 through 7.2.12, 7.4.0 through 7.4.10, and 7.6.0 through 7.6.5, update to a version that fixes the authentication bypass.
For FortiProxy versions 7.0.0 through 7.0.22, 7.2.0 through 7.2.15, 7.4.0 through 7.4.12, and 7.6.0 through 7.6.4, update to a version that fixes the authentication bypass.
For FortiWeb versions 7.4.0 through 7.4.11, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.3, update to a version that fixes the authentication bypass.
As a temporary mitigation, disable FortiCloud SSO for non-essential systems.
Enforce multi-factor authentication (MFA) for all administrative and VPN accounts.
Rotate all administrative credentials and terminate all active sessions.
Remove management interfaces and SSL VPN access from the public internet.
Monitor logs for unauthorized configuration changes or abnormal login activity.
Fix
LPE
RCE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortianalyzer
Fortimanager
Fortios