Historical catalog analysis: CISA added this entry on January 27, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-24858 is an authentication bypass vulnerability (CWE-288) affecting several Fortinet products. The flaw involves an alternate path or channel that allows an attacker who possesses a FortiCloud account and a registered device to authenticate into other devices registered to different accounts.
Exposure and applicability
This vulnerability specifically affects the following products:
* FortiOS
* FortiManager
* FortiAnalyzer
* FortiProxy
Exposure is conditional: the vulnerability is applicable only if FortiCloud SSO authentication is enabled on the affected devices. Assets that do not utilize this specific SSO configuration are not subject to this bypass path.
Remediation priorities
Based on our analysis, defenders should prioritize actions based on the internet-accessibility of their assets and the current SSO configuration:
- Configuration Audit: Immediately identify all Fortinet assets where FortiCloud SSO is enabled. This is the primary prerequisite for exploitability.
- Vendor Mitigation: Apply mitigations according to vendor instructions. If a mitigation is unavailable for a specific version or deployment, our analysis suggests evaluating whether to discontinue use of the product until a fix is applied.
- Compromise Assessment: Because this vulnerability allows unauthorized access, applying a patch does not guarantee the system is clean. Defenders should perform a compromise assessment on all internet-accessible affected products to identify signs of prior unauthorized entry.
How to validate remediation
Verification must move beyond simple version checks. To ensure exposure has been reduced, defenders should:
* Verify Configuration State: Confirm that FortiCloud SSO is either disabled or updated to a version where the vendor has mitigated the bypass path.
* Audit Access Logs: Review authentication logs for anomalous logins originating from unexpected FortiCloud accounts.
* Validate Mitigation Application: Use vendor-provided tools or documentation to confirm that the specific mitigation steps were successfully executed on each individual asset.
Limits and open questions
There is currently no confirmed data regarding whether ransomware campaigns are utilizing this vulnerability. Furthermore, while mitigations may be available, there is a residual risk that attackers may have already established persistence prior to the application of these fixes. The effectiveness of any mitigation depends on the thoroughness of the subsequent compromise assessment.
Source and editorial note
CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability · Source date: January 27, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: January 30, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 22, 2026 at 00:36 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗