Summary
CVE-2026-24858 is a critical authentication bypass vulnerability (CWE-288) affecting multiple Fortinet products, including FortiWeb, FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. The flaw exists in the FortiCloud single sign-on (SSO) authentication mechanism and carries a CVSS v3.1 score of 9.4. It has been actively exploited in the wild and is listed in CISA’s Known Exploited Vulnerabilities catalog with a remediation due date of January 30, 2026.
Technical details
- Root cause: The FortiCloud SSO authentication flow fails to enforce organizational boundaries between registered devices. When a device is registered to FortiCare via the management GUI, FortiCloud SSO login is enabled by default unless explicitly disabled at registration time.
- Trigger conditions: FortiCloud SSO authentication must be enabled on the target device (the default state for devices registered via the GUI). The attacker must possess any valid FortiCloud account with at least one registered device — an account that does not need to be associated with the target organization.
- Attack vector: Network-reachable management interface (HTTP/HTTPS). No privileges on the target device are required; the attacker authenticates through FortiCloud SSO and is granted access to devices belonging to other organizations.
- Impact: Full confidentiality, integrity, and availability compromise. In confirmed in-the-wild exploitation, attackers downloaded device configurations and created persistent administrative accounts on victim devices.
Affected software
- FortiWeb 8.0.0 through 8.0.3
- FortiWeb 7.6.0 through 7.6.6
- FortiWeb 7.4.0 through 7.4.11
- FortiOS 7.0.0 through 7.0.18, 7.2.0 through 7.2.12, 7.4.0 through 7.4.10, 7.6.0 through 7.6.5
- FortiManager 7.0.0 through 7.0.15, 7.2.0 through 7.2.11, 7.4.0 through 7.4.9, 7.6.0 through 7.6.5
- FortiAnalyzer 7.0.0 through 7.0.15, 7.2.0 through 7.2.11, 7.4.0 through 7.4.9, 7.6.0 through 7.6.5
- FortiProxy 7.0.0 through 7.0.22, 7.2.0 through 7.2.15, 7.4.0 through 7.4.12, 7.6.0 through 7.6.4
- FortiNAC-F 7.6.3 through 7.6.5
Severity
- CVSS v3.1 Score: 9.4 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
Mitigation and recommended actions
- Patch (FortiWeb): Upgrade to FortiWeb 8.0.4 or later. Consult Fortinet advisory FG-IR-26-060 for fix versions across all other affected product lines.
- Immediate workaround (if patching is not immediately possible): Disable FortiCloud SSO on all affected devices:
- FortiWeb / FortiOS / FortiProxy: Navigate to System → Settings and toggle off "Allow administrative login using FortiCloud SSO", or apply the equivalent CLI command per Fortinet’s advisory.
- FortiManager / FortiAnalyzer: Navigate to System Settings → SAML SSO and toggle off "Allow admins to login with FortiCloud".
- Per CISA guidance, check all internet-accessible Fortinet devices for signs of compromise — specifically unauthorized administrative accounts and unexpected configuration downloads — before applying patches.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

