fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-26-160 CVE-2026-70468
HIGH
Fortinet FortiManager and FortiManager Cloud Authentication Bypass Using an Alternate Path or Channel
Record summary
CVE-2026-70468 has a selected CVSS score of 7.3 (high).
Description
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FortiManagerBrowse Fortinet / FortiManagerDefault status: unaffected | CVE List | 7.6.1 | affected |
| 7.4.3 to ≤ 7.4.5 | affected | ||
| 7.2.5 to ≤ 7.2.9 | affected | ||
FortiManager CloudBrowse Fortinet / FortiManager CloudDefault status: unaffected | CVE List | 7.6.1 | affected |
| 7.4.3 to ≤ 7.4.5 | affected | ||
| 7.2.5 to ≤ 7.2.9 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70468