Improper Cryptographic Signature Validation in Fortinet FortiWeb Products
CVE-2025-59719

9.1CRITICAL

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-59719?

A flaw in Fortinet's FortiWeb products allows an unauthenticated attacker to exploit improper verification of cryptographic signatures. By crafting a malicious SAML response message, attackers can potentially bypass FortiCloud Single Sign-On (SSO) login authentication, leading to unauthorized access. This vulnerability affects specific versions of FortiWeb, highlighting the importance of prompt updates and mitigations by users.

Affected Version(s)

FortiWeb 8.0.0

FortiWeb 7.6.0 <= 7.6.4

FortiWeb 7.4.0 <= 7.4.9

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.