Race condion in FortiCloud SSO SAML authentication

Summary

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in FortiAnalyzer may allow an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.10 Upgrade to 7.2.11 or above
FortiAnalyzer 7.0 7.0.9 through 7.0.13 Upgrade to 7.0.14 or above
FortiAnalyzer 6.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Qi Fan of Fortinet FortiAnalyzer development team.

Timeline

2025-10-14: Initial publication