Authentication Lockout Bypass via Race Condition

Summary

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiManager and FortiAnalyzer may allow an attacker to bypass bruteforce protections via exploitation of race conditions.

Version Affected Solution
FortiAnalyzer 8.0 Not affected Not Applicable
FortiAnalyzer 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above
FortiAnalyzer 7.4 7.4 all versions Migrate to a fixed release
FortiAnalyzer 7.2 7.2 all versions Migrate to a fixed release
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer Cloud 8.0 Not affected Not Applicable
FortiAnalyzer Cloud 7.6 7.6.2 Upgrade to 7.6.5 or above
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.7 Migrate to a fixed release
FortiAnalyzer Cloud 7.2 7.2.1 through 7.2.10 Migrate to a fixed release
FortiAnalyzer Cloud 7.0 7.0.1 through 7.0.14 Migrate to a fixed release
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiManager 8.0 Not affected Not Applicable
FortiManager 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above
FortiManager 7.4 7.4 all versions Migrate to a fixed release
FortiManager 7.2 7.2 all versions Migrate to a fixed release
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager Cloud 8.0 Not affected Not Applicable
FortiManager Cloud 7.6 7.6.2 through 7.6.3 Upgrade to 7.6.5 or above
FortiManager Cloud 7.4 7.4.1 through 7.4.7 Migrate to a fixed release
FortiManager Cloud 7.2 7.2.1 through 7.2.10 Migrate to a fixed release
FortiManager Cloud 7.0 7.0.1 through 7.0.14 Migrate to a fixed release
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Discovered during an independent product security audit commissioned by Fortinet.

Timeline

2026-03-10: Initial publication