ZeroHour
Fortinet PSIRTpublished ()ingested

JWT used for authentication in web GUI signed with static key

highAdvisoryimportance 45
AI summary · glm-5.3

Fortinet warns that FortiMonitorOnSight's web GUI uses JWTs signed with a static key, enabling remote unauthenticated authentication bypass.

Fortinet advisory FG-IR-26-170 discloses a CVSS 9.6 vulnerability (CWE-540, sensitive information in source code) in the FortiMonitorOnSight web portal. The web GUI's JWT authentication tokens are signed with a static key, allowing a remote unauthenticated attacker to bypass authentication via forged or reused JWTs. The advisory was revised on September 8, 2026.

  • CVSS 9.6 flaw in FortiMonitorOnSight web portal
  • JWTs signed with static key allow forged-token authentication bypass
Full article

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.