LDAP authentication bypass in Agentless VPN and FSSO
CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-07-04 00:00:00
CSIRTS triage
- What
- An authentication bypass vulnerability may allow unauthenticated attackers to bypass LDAP authentication.
- Who is affected
- Deployments of FortiOS with specific LDAP server configurations.
- Urgency
- Remediation is urgent due to a CVSS score of 7.5 indicating high severity.
- Action
- Apply the latest patches to FortiOS.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiOS
Get an email when a new FortiOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-1052
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-221530.70% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-22153 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownBroken access control in the RADIUS type admin group2026-08-12
- unknownUI DoS attack2026-08-12