CVE-2026-70468

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, F

Severity
High 7.3
CVSS 3.1
Exploited
Not listed
EPSS
0.006
45.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
Aug 12, 2026
Assigned by fortinet

Description

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-288

Affected products

Vendor Product Category Matched by
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiManager
  • Fortinet · FortiManager Cloud

Credit

Internal

Vendor remediation

Upgrade to FortiManager Cloud version 7.6.2 or above Upgrade to FortiManager Cloud version 7.4.6 or above Upgrade to FortiManager Cloud version 7.2.10 or above Upgrade to FortiManager version 7.6.2 or above Upgrade to FortiManager version 7.4.6 or above Upgrade to FortiManager version 7.2.10 or above

Something wrong here?