Skip to content
FortinetCVE-2026-70468

Fortinet FortiManager: authentication bypass

High8.1CVE-2026-70468 · Published Aug 12, 2026 · updated Sep 8, 2026

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

Fortinet advisory

Affected versions

PackageAffectedFixed in
FortiManager
Product
<= 7.6.1No fix yet
>= 7.4.3, <= 7.4.5No fix yet
>= 7.2.5, <= 7.2.9No fix yet
FortiManager Cloud
Product
<= 7.6.1No fix yet
>= 7.4.3, <= 7.4.5No fix yet
>= 7.2.5, <= 7.2.9No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-288

More Fortinet advisories

All Fortinet
Advisory
Fortinet FortiSIEM: server-side request forgery
Low3.8Aug 12
Fortinet FortiOS: stack buffer overflow
Medium5.6Aug 12
Fortinet FortiOS: denial of service
Medium5.3Aug 12
Fortinet FortiWeb: improper access control
Medium5.3Aug 12
Fortinet FortiWeb: improper authentication
Critical9.8Aug 12
Fortinet FortiClientWindows: buffer overflow
High8.1Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.