SecBoard
Zurück zur CVE-Übersicht

CVE-2026-24858

CRITICAL(9.8)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score80/100 — KRITISCH
  • CVSS 9.8 — Kritisch
  • EPSS 86% — sehr wahrscheinlich ausgenutzt
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

86.1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

SecBoard-Einordnung

Die Schwachstelle CVE-2026-24858 betrifft mehrere Fortinet-Produkte, darunter FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy und FortiWeb. Es handelt sich um eine Authentifizierungs-Bypass-Schwachstelle (CWE-288), die es einem Angreifer mit einem FortiCloud-Konto und einem registrierten Gerät ermöglichen kann, sich bei anderen Geräten anzumelden, die bei anderen Konten registriert sind, sofern die FortiCloud SSO-Authentifizierung auf diesen Geräten aktiviert ist. Die potenzielle Auswirkung ist ein unautorisierter Zugriff auf betroffene Systeme.

Diese Schwachstelle ist als kritisch einzustufen, mit einem CVSS-Score von 9.8. Die Exploit-Wahrscheinlichkeit ist mit einem EPSS-Wert von 86% sehr hoch. Besonders besorgniserregend ist, dass diese Schwachstelle in der () Datenbank gelistet ist, was bedeutet, dass sie aktiv ausgenutzt wird und ein unmittelbares Risiko darstellt.

Security-Teams sollten umgehend prüfen, ob FortiCloud SSO-Authentifizierung auf ihren Fortinet-Geräten aktiviert ist und welche der genannten Produkte in den betroffenen Versionen im Einsatz sind. Eine sofortige Implementierung verfügbarer Patches oder die Deaktivierung der FortiCloud SSO-Authentifizierung, falls keine Patches verfügbar sind, ist dringend erforderlich, um das Risiko einer aktiven Ausnutzung zu minimierung. Zudem sollte eine Überwachung auf ungewöhnliche Anmeldeversuche oder Aktivitäten erfolgen.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Referenzen