سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-24858

تجاوز مصادقة عبر FortiCloud في منتجات فورتينت المتعددة

حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

يستطيع مهاجم يملك حساب FortiCloud وجهازًا مسجّلًا تسجيل الدخول إلى أجهزة FortiOS وFortiProxy وFortiManager وFortiAnalyzer أخرى في الحساب نفسه دون بيانات اعتمادها.

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
Multiple Products

التغطية على سيبرانا