CVE-2026-22153

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentl

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.007
52.1th percentile
Discovered by
Third party
Vendor advisory field
Published
Feb 10, 2026
Assigned by fortinet

Description

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

Weakness: CWE-305

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiOS

Credit

Fortinet is pleased to thank Jort Geurts from the Actemium Cyber Security Team for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.5 or above

Something wrong here?