FGFM Authentication Weakening via CLI Configuration
CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00
CSIRTS triage
- What
- An authentication bypass vulnerability allows a remote unauthenticated attacker to impersonate any FortiGate managed by FortiManager when a specific CLI option is set, if the attacker possesses a valid certificate.
- Who is affected
- FortiManager and FortiManager Cloud deployments with the vulnerable CLI option configured.
- Urgency
- Moderately urgent; exploitation requires both a valid certificate and specific configuration, but grants full impersonation capability.
- Action
- Apply patches from Fortinet and review CLI configurations to disable the vulnerable option if applicable.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiManager
Get an email when a new FortiManager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-160
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704680.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70468 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManagerncsc-nl
- high[NEW] [high] Fortinet FortiManager: Vulnerability enables bypass of security measurescert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- highCVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiMana…nvd
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownStack buffer overflow in WAD2026-08-12
- unknownHTTP/2 Bomb CVE-2026-499752026-08-12