Authentication Bypass Vulnerability in Fortinet FortiAnalyzer and FortiManager Products
CVE-2026-22572
6.8MEDIUM
What is CVE-2026-22572?
An authentication bypass vulnerability exists within Fortinet's FortiAnalyzer and FortiManager that allows an attacker, aware of the admin's password, to circumvent multifactor authentication. This is achieved by sending multiple crafted requests, potentially compromising the security of the affected systems. Fortinet recommends immediate updates to the latest secure versions to mitigate this risk.
Affected Version(s)
FortiAnalyzer 7.6.0 <= 7.6.3
FortiAnalyzer 7.4.0 <= 7.4.7
FortiAnalyzer 7.2.2 <= 7.2.12