Improper Cryptographic Signature Validation in Fortinet FortiWeb Products
CVE-2025-59719
9.1CRITICAL
What is CVE-2025-59719?
A flaw in Fortinet's FortiWeb products allows an unauthenticated attacker to exploit improper verification of cryptographic signatures. By crafting a malicious SAML response message, attackers can potentially bypass FortiCloud Single Sign-On (SSO) login authentication, leading to unauthorized access. This vulnerability affects specific versions of FortiWeb, highlighting the importance of prompt updates and mitigations by users.
Affected Version(s)
FortiWeb 8.0.0
FortiWeb 7.6.0 <= 7.6.4
FortiWeb 7.4.0 <= 7.4.9