CVE-2026-70468

Summary

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

Affected Software

VendorProductVersion RangeStatus
FortinetFortiManager7.6.1affected
FortinetFortiManager7.4.3 <= 7.4.5affected
FortinetFortiManager7.2.5 <= 7.2.9affected
FortinetFortiManager Cloud7.6.1affected
FortinetFortiManager Cloud7.4.3 <= 7.4.5affected
FortinetFortiManager Cloud7.2.5 <= 7.2.9affected

Weaknesses

  • CWE-288: Improper access control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References