CVE-2026-70468
Received
Received - Intake
Authentication Bypass in Fortinet FortiManager
Vulnerability report for CVE-2026-70468, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-12
Last updated on: 2026-08-12
Assigner: Fortinet, Inc.
Description
Description
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortimanager | 7.6.1 |
| fortinet | fortimanager | From 7.4.3 (inc) to 7.4.5 (inc) |
| fortinet | fortimanager | From 7.2.5 (inc) to 7.2.9 (inc) |
| fortinet | fortimanager_cloud | 7.6.1 |
| fortinet | fortimanager_cloud | From 7.4.3 (inc) to 7.4.5 (inc) |
| fortinet | fortimanager_cloud | From 7.2.5 (inc) to 7.2.9 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |