CVE-2025-59718
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
- EPSS probability
- 68.29%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-347
- Published
- 2025-12-09
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
Weakness type
Related vulnerabilities
- CVE-2026-48558 — SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
- CVE-2026-33746 — Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users
- CVE-2026-31946 — OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
- CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2026-4478 — Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
- CVE-2026-34377 — Zebra has a Consensus Failure due to Improper Verification of V5 Transactions
- CVE-2026-56451 — A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate
- CVE-2026-54782 — CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation