CVE-2026-22572
EUVD-2026-1051110.03.2026, 18:18
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortianalyzer | 7.2.2 ≤ 𝑥 < 7.4.8 |
| fortinet | fortianalyzer | 7.6.0 ≤ 𝑥 < 7.6.4 |
| fortinet | fortimanager | 7.2.2 ≤ 𝑥 < 7.4.8 |
| fortinet | fortimanager | 7.6.0 ≤ 𝑥 < 7.6.4 |
| fortinet | fortimanager_cloud | 7.2.2 ≤ 𝑥 < 7.4.8 |
| fortinet | fortimanager_cloud | 7.6.0 ≤ 𝑥 < 7.6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration