Multiple Fortinet Products: FortiCloud SSO Login Authentication Bypass / CVSS:9.4

Last Update: 06.02.2026: Added Analysis Report Link


Fortinet has published information about a new vulnerability affecting FortiOS, FortiProxy, FortiSwitchManager and FortiWeb. Affected devices require specific firmware patches and the “Allow administrative login using FortiCloud SSO” setting must be enabled. Patches to fix the issue already exist.

If you are using an affected release, you must immediately take action by either performing an upgrade or disabling the “Allow administrative login using FortiCloud SSO” setting, using one of the two methods below:

1. Via Graphical User Interface (GUI)

Use the following navigation path to disable the function through the web interface:

  • Navigate to: System –> Settings
  • Under the Single Sign-On section, locate the FortiCloud SSO option.
  • Set the toggle switch to Disable.

2. Via Command Line Interface (CLI)

Execute the following commands in the CLI to adjust the global configuration:

config system global
set admin-forticloud-sso-login disable
end

PSIRT information

https://fortiguard.fortinet.com/psirt/FG-IR-25-647

IR NumberFG-IR-25-647
Published DateDec 9, 2025
ComponentGUI
SeverityCritical
CVSSv3 Score9.1
ImpactImproper access control
CVE IDCVE-2025-59718, CVE-2025-59719

Affected and patched releases

VersionAffectedSolution
FortiOS 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiOS 7.47.4.0 through 7.4.8Upgrade to 7.4.9 or above
FortiOS 7.27.2.0 through 7.2.11Upgrade to 7.2.12 or above
FortiOS 7.07.0.0 through 7.0.17Upgrade to 7.0.18 or above
FortiOS 6.4Not affectedNot Applicable
FortiProxy 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiProxy 7.47.4.0 through 7.4.10Upgrade to 7.4.11 or above
FortiProxy 7.27.2.0 through 7.2.14Upgrade to 7.2.15 or above
FortiProxy 7.07.0.0 through 7.0.21Upgrade to 7.0.22 or above
FortiSwitchManager 7.27.2.0 through 7.2.6Upgrade to 7.2.7 or above
FortiSwitchManager 7.07.0.0 through 7.0.5Upgrade to 7.0.6 or above
FortiWeb 8.08.0.0Upgrade to 8.0.1 or above
FortiWeb 7.67.6.0 through 7.6.4Upgrade to 7.6.5 or above
FortiWeb 7.47.4.0 through 7.4.9Upgrade to 7.4.10 or above
FortiWeb 7.2Not affectedNot Applicable
FortiWeb 7.0Not affectedNot Applicable

Fortinet has published an Analysis Report for the FortiCloud SSO vulnerability.

Loading

Leave a Reply

Your email address will not be published. Required fields are marked *