CVE-2024-26011

CRITICAL

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 t...

Affects 6 products across 3 vendors.

BCS6.8
CVSS 3.19.8
EPSS0.6%
Percentile45th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Fortinet FortiManager, FortiPAM, FortiProxy, FortiSwitchManager, FortiPortal, and FortiOS allows an attacker to execute unauthorized code or commands via specially crafted packets. This vulnerability affects multiple versions of these products and has a CVSS score of 9.8, indicating a high severity. Immediate action is required to mitigate the risk of exploitation.

BSID: BS-2024-GLOBAL-045284-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-26011?
A critical vulnerability in Fortinet FortiManager, FortiPAM, FortiProxy, FortiSwitchManager, FortiPortal, and FortiOS allows an attacker to execute unauthorized code or commands via specially crafted packets. This vulnerability affects multiple versions of these products and has a CVSS score of 9.8, indicating a high severity. Immediate action is required to mitigate the risk of exploitation.
What is the CVSS score for CVE-2024-26011?
CVE-2024-26011 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2024-26011 actively exploited?
No confirmed active exploitation of CVE-2024-26011 as of 2026-05-30.
How do I remediate CVE-2024-26011?
Priority: IMMEDIATE. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-24-032 PSIRT: [email protected]
What systems are affected by CVE-2024-26011?
CVE-2024-26011 affects: Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2024-26011?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to critical functions, which can compromise the security and reliability of the control system.
What IEC 62443 requirement maps to CVE-2024-26011?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a lack of authentication for critical functions, which is a fundamental security requirement to prevent unauthorized access and control.
Vulnerability Details
CVE IDCVE-2024-26011
BSIDBS-2024-GLOBAL-045284-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-11-12
Last Modified2024-12-12
ICS Relevance70%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is due to a missing authentication for critical functions in the affected Fortinet products. An attacker can exploit this vulnerability by sending specially crafted packets to the affected systems, leading to the execution of unauthorized code or commands. The attack can be performed remotely without any user interaction, and no authentication is required to exploit the vulnerability.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fortinet Fortipam
Fortinet Fortios
Fortinet Fortimanager
Fortinet Fortiportal
Fortinet Fortiproxy
Fortinet Fortiswitchmanager
Fujitsu-Siemens —
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 620 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and access controls to limit exposure to the affected systems. Monitor network traffic for suspicious activity and apply the latest vendor patches as soon as they are available.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to critical functions, which can compromise the security and reliability of the control system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a lack of authentication for critical functions, which is a fundamental security requirement to prevent unauthorized access and control.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash1097440431ae92ba22724a8bd139aa7741f0503f01f75332e35f1d7b9c67e3f3fb5bcd55fa82c89534b0505c4be795cb6200416fcff528eaabe6d0e19caf7628
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →