CVE-2026-24858
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2...
Affects 7 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical Authentication Bypass vulnerability exists in multiple versions of Fortinet products, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. This vulnerability allows an attacker with a FortiCloud account and a registered device to log into other devices registered to different accounts if FortiCloud SSO authentication is enabled. The CVSS score is 9.8, indicating a high severity level. Immediate action is required to mitigate the risk of unauthorized access and potential compromise of affected systems.
BSID: BS-2026-GLOBAL-072918-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-24858?
What is the CVSS score for CVE-2026-24858?
Is CVE-2026-24858 actively exploited?
How do I remediate CVE-2026-24858?
What systems are affected by CVE-2026-24858?
What NERC-CIP standard applies to CVE-2026-24858?
What IEC 62443 requirement maps to CVE-2026-24858?
| CVE ID | CVE-2026-24858 |
|---|---|
| BSID | BS-2026-GLOBAL-072918-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-01-27 |
| Last Modified | 2026-05-12 |
| ICS Relevance | 85% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited by an attacker with a FortiCloud account and a registered device. If FortiCloud SSO authentication is enabled on the target device, the attacker can bypass the authentication mechanism and gain unauthorized access to the device. This can lead to full control over the device, allowing the attacker to perform actions such as modifying configurations, accessing sensitive data, and disrupting operations.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Fortinet | Fortimanager | — |
| Fortinet | Fortianalyzer | — |
| Fortinet | Fortiproxy | — |
| Fortinet | Fortios | — |
| Fortinet | Fortiweb | — |
| Siemens | Ruggedcom Ape1808 | — |
| Siemens | Ruggedcom Ape1808 Firmware | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2026-01-27) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access controls and monitor FortiCloud SSO authentication attempts. Ensure that only authorized users can register devices and that device registration is tightly controlled. Regularly review logs for suspicious activity and consider implementing multi-factor authentication for additional security.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to critical cyber assets, which could lead to the compromise of the asset's integrity and availability.
This CVE maps to SR 7.6 because it involves an authentication bypass, which can lead to unauthorized access to the system. Proper authentication mechanisms are essential to ensure that only authorized personnel can access the system, maintaining the confidentiality, integrity, and availability of the control system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 62f01a8b5e5185882d20b19f7bb6281318689e620fb345e87bba6b424b7cceda1566936c5805704ab1084e8d671386a64d186ce75b9430bbb8076e9560bd5df3 |
This Vulnerability Is Being Actively Exploited
CVE-2026-24858 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →