
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22572 is an authentication bypass vulnerability (CWE-288: Authentication Bypass Using an Alternate Path or Channel) in Fortinet FortiAnalyzer and FortiManager that allows an attacker with knowledge of an administrator's password to bypass multifactor authentication (MFA) checks by submitting multiple crafted requests. Affected products include FortiAnalyzer 7.2.2–7.2.11, 7.4.0–7.4.7, and 7.6.0–7.6.3; FortiManager 7.2.2–7.2.11, 7.4.0–7.4.7, and 7.6.0–7.6.3; and FortiManager Cloud/FortiAnalyzer Cloud across the same version ranges. The vulnerability was disclosed on March 10, 2026, and was discovered during an internal product security audit commissioned by Fortinet. It carries a CVSSv3.1 base score of 6.8 (Medium) per the vendor advisory, though NVD rates it at 7.2 (High) (Fortinet PSIRT, Feedly).
The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and resides in the GUI component of FortiManager and FortiAnalyzer's MFA implementation. An attacker who already possesses a valid administrator password can submit multiple specially crafted authentication requests to circumvent the MFA verification step, effectively gaining access without completing the second factor. Exploitation requires network access and prior knowledge of administrator credentials (high privilege precondition), but no user interaction is needed. No public proof-of-concept code has been identified (Fortinet PSIRT).
Successful exploitation grants an attacker unauthorized administrative access to FortiAnalyzer or FortiManager deployments, bypassing the MFA control that serves as a critical second layer of defense. This could allow manipulation of security configurations, access to sensitive log and analytics data, compromise of managed network device configurations, and potential disruption of security monitoring infrastructure. The confidentiality, integrity, and availability of managed security infrastructure are all at risk (Fortinet PSIRT, Feedly).
Fortinet has released patched versions addressing this vulnerability. Users should upgrade to the following fixed releases: FortiAnalyzer 7.6.4 or above, FortiAnalyzer 7.4.8 or above (FortiAnalyzer 7.2.x users should migrate to a fixed release); FortiManager 7.6.4 or above, FortiManager 7.4.8 or above (FortiManager 7.2.x users should migrate to a fixed release); FortiManager Cloud 7.2.11 or above, 7.4.8 or above, or 7.6.4 or above. As interim measures, restrict administrative GUI access to trusted networks only using firewall rules, enforce strong unique administrator passwords, monitor authentication logs for anomalous MFA bypass patterns, and disable unused administrator accounts (Fortinet PSIRT).
Coverage of CVE-2026-22572 has been limited to security news aggregators and vulnerability tracking platforms, with no notable independent researcher commentary or significant social media discussion identified. Security news outlets such as CyberSecurityNews and TheDailyTechFeed covered it as part of broader Fortinet March 2026 patch roundups. The vulnerability was discovered internally by Fortinet through a commissioned product security audit, which the vendor disclosed proactively (Fortinet PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."