Authentication bypass using an alternate path or channel in FortiManager and FortiAnalyzer - CVE-2026-22572

 

Authentication bypass using an alternate path or channel in FortiManager and FortiAnalyzer - CVE-2026-22572

Published: March 10, 2026


Vulnerability identifier: #VU123723
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22572
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass 2FA authentication checks.

The vulnerability exists due to authentication bypass using an alternate path or channel in GUI. A remote  attacker with knowledge of the admins password can bypass multifactor authentication checks via submitting multiple crafted requests and gain unauthorized access to the system.


Affected software

FortiManager
FortiAnalyzer

How to mitigate CVE-2026-22572

Install updates from vendor's website.

FortiManager - addressed in versions 7.4.8, 7.6.4
FortiAnalyzer - addressed in versions 7.4.8, 7.6.4

External References

Related Security Bulletins