Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiPAM
CVE-2024-26009

8.1HIGH

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
12 August 2025

What is CVE-2024-26009?

An authentication bypass vulnerability exists in Fortinet's FortiOS, FortiProxy, and FortiPAM products, allowing unauthenticated attackers to potentially gain control of managed devices. This vulnerability arises when crafted FGFM requests are sent to devices managed by FortiManager, particularly if the attacker has the FortiManager’s serial number. The issue affects specific versions of FortiOS, FortiProxy, and FortiPAM. It is crucial for organizations to review their systems and apply necessary security measures to mitigate this risk.

Affected Version(s)

FortiOS 6.4.0 <= 6.4.15

FortiOS 6.2.0 <= 6.2.16

FortiOS 6.0.0 <= 6.0.18

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.