CVE-2026-24858
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 86% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
86.1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
Die Schwachstelle CVE-2026-24858 betrifft mehrere Fortinet-Produkte, darunter FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy und FortiWeb. Es handelt sich um eine Authentifizierungs-Bypass-Schwachstelle (CWE-288), die es einem Angreifer mit einem FortiCloud-Konto und einem registrierten Gerät ermöglichen kann, sich bei anderen Geräten anzumelden, die bei anderen Konten registriert sind, sofern die FortiCloud SSO-Authentifizierung auf diesen Geräten aktiviert ist. Die potenzielle Auswirkung ist ein unautorisierter Zugriff auf betroffene Systeme.
Diese Schwachstelle ist als kritisch einzustufen, mit einem CVSS-Score von 9.8. Die Exploit-Wahrscheinlichkeit ist mit einem EPSS-Wert von 86% sehr hoch. Besonders besorgniserregend ist, dass diese Schwachstelle in der CISA Known Exploited Vulnerabilities (KEV) Datenbank gelistet ist, was bedeutet, dass sie aktiv ausgenutzt wird und ein unmittelbares Risiko darstellt.
Security-Teams sollten umgehend prüfen, ob FortiCloud SSO-Authentifizierung auf ihren Fortinet-Geräten aktiviert ist und welche der genannten Produkte in den betroffenen Versionen im Einsatz sind. Eine sofortige Implementierung verfügbarer Patches oder die Deaktivierung der FortiCloud SSO-Authentifizierung, falls keine Patches verfügbar sind, ist dringend erforderlich, um das Risiko einer aktiven Ausnutzung zu minimierung. Zudem sollte eine Überwachung auf ungewöhnliche Anmeldeversuche oder Aktivitäten erfolgen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.