ZeroHour
Fortinet PSIRTpublished ()ingested

FGFM Authentication Weakening via CLI Configuration

mediumAdvisoryimportance 40
AI summary · glm-5.3-flash

FortiManager FGFM flaw (CVSS 7.3) lets an attacker with a valid certificate impersonate any managed FortiGate under a specific CLI option.

Fortinet advisory FG-IR-26-160 describes an authentication bypass via alternate path (CWE-288) in FortiManager and FortiManager Cloud, scored CVSSv3 7.3. A remote unauthenticated attacker holding a valid certificate can impersonate any FortiGate managed by the affected FortiManager when a specific CLI option is set. The impersonation is performed with crafted FGFM protocol requests. The advisory was revised on 2026-08-12 and does not report active exploitation.

  • Authentication bypass (CWE-288) in FortiManager and FortiManager Cloud
  • Valid-certificate holder can impersonate any managed FortiGate via FGFM
  • Requires a specific CLI option to be set; CVSSv3 7.3
Full article

CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.