CVE-2024-26009

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, Fo

Severity
High 7.9
CVSS 3.1
Exploited
Not listed
EPSS
0.006
47.0th percentile
Discovered by
Vendor
Vendor advisory field
Published
Aug 12, 2025
Assigned by fortinet

Description

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number.

Weakness: CWE-288

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported products (4)
  • Fortinet · FortiProxy
  • Fortinet · FortiOS
  • Fortinet · FortiPAM
  • Fortinet · FortiSwitchManager

Credit

Internally discovered and reported by Adham El Karn & Théo Leleu of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiSwitchManager version 7.2.4 or above Upgrade to FortiSwitchManager version 7.0.4 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiOS version 6.2.17 or above Upgrade to FortiManager version 7.0.12 or above Upgrade to FortiManager version 6.4.15 or above Upgrade to FortiPAM version 1.3.0 or above Upgrade to FortiProxy version 7.4.3 or above Upgrade to FortiProxy version 7.2.9 or above Upgrade to FortiProxy version 7.0.16 or above

Something wrong here?