# CVE-2026-24858

## Summary

- **CVE ID:** CVE-2026-24858
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C)
- **CWE:** CWE-288
- **Published:** Jan 27, 2026
- **Last Modified:** Jun 9, 2026

## Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

## Affected Products

- Fortinet — FortiProxy (7.2.0)
- Fortinet — FortiManager (7.6.0)
- Fortinet — FortiManager (7.4.0)
- Fortinet — FortiManager (7.2.0)
- Fortinet — FortiManager (7.0.0)
- Fortinet — FortiOS (7.6.0)
- Fortinet — FortiOS (7.4.0)
- Fortinet — FortiOS (7.2.0)
- Fortinet — FortiOS (7.0.0)
- Fortinet — FortiProxy (7.6.0)
- Fortinet — FortiProxy (7.4.0)
- Fortinet — FortiProxy (7.0.0)
- Fortinet — FortiAnalyzer (7.6.0)
- Fortinet — FortiAnalyzer (7.4.0)
- Fortinet — FortiAnalyzer (7.2.0)
- Fortinet — FortiAnalyzer (7.0.0)
- Fortinet — FortiWeb (8.0.0)
- Fortinet — FortiWeb (7.6.0)
- Fortinet — FortiWeb (7.4.0)
- Fortinet — FortiNAC-F (7.6.3)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-26-060)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24858)
- [CISA-ADP](https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-975644.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 86.09%
- **EPSS Percentile:** 99.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jan 27, 2026
- **Due Date:** Jan 30, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._