CVE-2025-59719
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
- EPSS probability
- 29.22%
- CWE
- CWE-347
- Published
- 2025-12-09
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
Weakness type
Related vulnerabilities
- CVE-2026-48558 — SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
- CVE-2026-33746 — Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users
- CVE-2026-31946 — OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
- CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2026-4478 — Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
- CVE-2026-34377 — Zebra has a Consensus Failure due to Improper Verification of V5 Transactions
- CVE-2026-56451 — A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate
- CVE-2026-54782 — CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation