CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

FGFM Authentication Weakening via CLI Configuration

unknownCVE-2026-70468
CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00

CSIRTS triage

What
An authentication bypass vulnerability allows a remote unauthenticated attacker to impersonate any FortiGate managed by FortiManager when a specific CLI option is set, if the attacker possesses a valid certificate.
Who is affected
FortiManager and FortiManager Cloud deployments with the vulnerable CLI option configured.
Urgency
Moderately urgent; exploitation requires both a valid certificate and specific configuration, but grants full impersonation capability.
Action
Apply patches from Fortinet and review CLI configurations to disable the vulnerable option if applicable.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FortiManager

Get an email when a new FortiManager advisory drops — max one per day, one-click unsubscribe.

Details

Source
Fortinet FortiGuard PSIRT (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync

Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-160

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-70468coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Fortinet FortiGuard PSIRT