CVE-2026-70468
Fortinet FortiManager vulnerability analysis and mitigation

Overview

CVE-2026-70468 is an authentication bypass vulnerability (CWE-288) in Fortinet FortiManager and FortiManager Cloud that allows network-based attackers to bypass authentication via an alternate path or channel, resulting in improper access control. Affected versions include FortiManager 7.6.1, 7.4.3–7.4.5, and 7.2.5–7.2.9, as well as the corresponding FortiManager Cloud versions. The vulnerability was published on August 12, 2026, with Fortinet's advisory tracked as FG-IR-26-160. It carries a CVSS v3.1 base score of 8.1 (High) (Fortinet PSIRT, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the product enforces authentication on primary paths but exposes an alternate path or channel that does not require valid credentials. The attack is network-based, requires no privileges and no user interaction, but has high attack complexity, suggesting that exploitation requires specific conditions or knowledge of the alternate channel. The exact attack vector details (the specific alternate path or endpoint) were not fully disclosed in the public advisory at time of publication, as the CVE description contains a placeholder (GitHub Advisory, Fortinet PSIRT). A proof-of-concept or technical write-up has been published by Beazley Security Labs (Beazley Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to bypass authentication mechanisms and gain unauthorized access to FortiManager or FortiManager Cloud management interfaces. This can result in high confidentiality, integrity, and availability impacts — including unauthorized reading of sensitive network configuration and managed device data, modification of management settings, and potential disruption of the FortiManager service. Given FortiManager's role as a centralized network management platform, compromise could enable lateral movement to managed FortiGate devices and downstream network infrastructure (GitHub Advisory, SecurityWeek).

Exploitability

A proof-of-concept or exploitation details have been reported by Beazley Security Labs (Beazley Advisory). NVD's supplemental data indicates no confirmed in-the-wild exploitation at time of initial publication, though exploitation has been referenced by multiple threat intelligence sources. The EPSS score is approximately 0.587% (46th percentile), indicating a moderate near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog based on available data. Attack complexity is rated High, meaning exploitation is not trivially automatable (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-exposed FortiManager or FortiManager Cloud instances running affected versions (7.6.1, 7.4.3–7.4.5, or 7.2.5–7.2.9) using tools such as Shodan or Censys, targeting the FGFM management port (typically TCP 541) or web management interfaces.
  2. Identify alternate authentication path: Research or leverage published details (e.g., Beazley Security Labs advisory BSL-A1198) to identify the specific alternate path, endpoint, or channel in FortiManager that bypasses standard authentication controls.
  3. Craft bypass request: Send a specially crafted network request to the identified alternate path or channel without providing valid credentials, exploiting the missing authentication enforcement on that route.
  4. Achieve unauthorized access: Upon successful bypass, interact with FortiManager's management API or interface to read sensitive configurations, modify managed device policies, or perform administrative actions across managed FortiGate devices (Beazley Advisory, Fortinet PSIRT).

Indicators of compromise

  • Network: Unexpected or anomalous connections to FortiManager management interfaces (TCP 541/FGFM or HTTPS management port) from untrusted or external IP addresses; requests to unusual or undocumented API endpoints without authentication headers.
  • Logs: FortiManager access logs showing successful administrative sessions from unknown or unauthorized source IPs without corresponding valid login events; authentication log entries showing access via non-standard paths or channels.
  • Process/Behavioral: Unexpected configuration changes to managed FortiGate devices or FortiManager policies not correlated with authorized administrator activity; new administrator accounts or modified access control lists created without change management records.
  • File System: Unexpected scripts or files written to FortiManager directories by the management process (Beazley Advisory, Fortinet PSIRT).

Mitigation and workarounds

Apply the patches released by Fortinet as referenced in advisory FG-IR-26-160; patched versions are available via the GitHub Advisory (GHSA-cv9f-9p28-r862), though specific fixed version numbers were not fully enumerated in public disclosures at time of writing. As an immediate workaround, restrict network access to FortiManager and FortiManager Cloud management interfaces (including FGFM port TCP 541 and web management) to only authorized IP addresses using firewall rules or access control lists. Monitor FortiManager access logs for suspicious authentication activity from unknown sources, and consider implementing network segmentation to limit exposure of management interfaces to the internet (Fortinet PSIRT, GitHub Advisory).

Community reactions

SecurityWeek covered the vulnerability as part of a broader report on Fortinet patching authentication flaws across multiple products including FortiWeb and FortiManager, noting the high severity of the issues (SecurityWeek). CyberSecurityNews, GBHackers, and CyberPress also reported on the Fortinet authentication vulnerability cluster, highlighting the risk to enterprise network management infrastructure. The H-ISAC issued a TLP:GREEN report on August 13, 2026, flagging Fortinet's high-severity patches across multiple products for healthcare sector awareness (H-ISAC). The Singapore Cyber Security Agency (CSA) also issued an alert (AL-2026-105) regarding the Fortinet vulnerabilities.

Additional resources


SourceThis report was generated using AI

Related Fortinet FortiManager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70468HIGH8.1
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortimanager
NoYesAug 12, 2026
CVE-2025-61848HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortimanager
NoYesApr 14, 2026
CVE-2025-68649MEDIUM6.5
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesApr 14, 2026
CVE-2025-67604MEDIUM5.3
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMay 12, 2026
CVE-2026-22629LOW3.7
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management