Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiPAM
CVE-2024-26009
8.1HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2024-26009?
An authentication bypass vulnerability exists in Fortinet's FortiOS, FortiProxy, and FortiPAM products, allowing unauthenticated attackers to potentially gain control of managed devices. This vulnerability arises when crafted FGFM requests are sent to devices managed by FortiManager, particularly if the attacker has the FortiManager’s serial number. The issue affects specific versions of FortiOS, FortiProxy, and FortiPAM. It is crucial for organizations to review their systems and apply necessary security measures to mitigate this risk.
Affected Version(s)
FortiOS 6.4.0 <= 6.4.15
FortiOS 6.2.0 <= 6.2.16
FortiOS 6.0.0 <= 6.0.18
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved