Authentication bypass using an alternate path or channel in FortiManager and FortiAnalyzer - CVE-2026-22572
Published: March 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass 2FA authentication checks.
The vulnerability exists due to authentication bypass using an alternate path or channel in GUI. A remote attacker with knowledge of the admins password can bypass multifactor authentication checks via submitting multiple crafted requests and gain unauthorized access to the system.
Affected software
FortiAnalyzer
How to mitigate CVE-2026-22572
FortiAnalyzer - addressed in versions 7.4.8, 7.6.4