Description
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
Published: 2026-08-12
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass that allows an attacker to obtain improper access control by exploiting an alternate path or channel in Fortinet FortiManager. The weakness is classified as CWE-288, indicating inadequate authentication. If successfully abused, an attacker could log in to the management console or perform privileged operations without the proper credentials, potentially compromising the security of multiple managed devices.

Affected Systems

Fortinet FortiManager and FortiManager Cloud are affected. Versions 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9 of FortiManager, as well as the corresponding Cloud releases, are listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity impact. EPSS data is not available, so the probability of exploitation is not quantified, but the vulnerability is not currently listed in CISA KEV, indicating no known widespread exploitation yet. The attack vector is not explicitly detailed in the advisory; based on the description it is inferred that the attacker would target an undocumented or alternate authentication endpoint or API. This path bypasses standard login controls, allowing unauthorized access that could lead to full administrative compromise of the fortified infrastructure.

Generated by OpenCVE AI on August 13, 2026 at 01:03 UTC.

Remediation

Vendor Solution

Upgrade to FortiManager Cloud version 7.6.2 or above Upgrade to FortiManager Cloud version 7.4.6 or above Upgrade to FortiManager Cloud version 7.2.10 or above Upgrade to FortiManager version 7.6.2 or above Upgrade to FortiManager version 7.4.6 or above Upgrade to FortiManager version 7.2.10 or above


OpenCVE Recommended Actions

  • Upgrade FortiManager to version 7.6.2 or later, or to 7.4.6 or later, or to 7.2.10 or later, depending on the current release.
  • Upgrade FortiManager Cloud to version 7.6.2 or later, or to 7.4.6 or later, or to 7.2.10 or later, depending on the current release.
  • If an immediate patch is unavailable, block network access to the alternate authentication endpoint or API paths that facilitate the bypass, and restrict management interface traffic to known, secure channels.

Generated by OpenCVE AI on August 13, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Alternate Path in FortiManager

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortimanager
Fortinet fortimanagercloud
Weaknesses CWE-288
CPEs cpe:2.3:a:fortinet:fortimanagercloud:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanagercloud:7.6.1:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.2.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.2.6:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.2.7:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.2.8:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.2.9:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.4.3:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.4.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.4.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortimanager:7.6.1:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortimanager
Fortinet fortimanagercloud
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortimanager Fortimanagercloud
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-08-13T03:55:29.713Z

Reserved: 2026-08-04T15:01:44.603Z

Link: CVE-2026-70468

cve-icon Vulnrichment

Updated: 2026-08-12T13:27:33.926Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T13:17:25.227

Modified: 2026-08-26T16:54:50.030

Link: CVE-2026-70468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:15:12Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel