CVE-2026-22572

An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiMan

Severity
Medium 6.8
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.006
44.8th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.

Weakness: CWE-288

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer Check your version SIEM & Log Management cna-assigner
Fortinet FortiManager Check your version Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer

Credit

Discovered during an independent product security audit commissioned by Fortinet.

Vendor remediation

Upgrade to FortiManager version 7.6.4 or above Upgrade to FortiManager version 7.4.8 or above Upgrade to FortiAnalyzer version 7.6.4 or above Upgrade to FortiAnalyzer version 7.4.8 or above

Something wrong here?