MFA Bypass in GUI

Summary

An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiManager and FortiAnalyzer multifactor authentication may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiAnalyzer 7.2 7.2.2 through 7.2.11 Migrate to a fixed release
FortiAnalyzer 6.4 Not affected Not Applicable
FortiManager 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiManager 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiManager 7.2 7.2.2 through 7.2.11 Migrate to a fixed release
FortiManager 6.4 Not affected Not Applicable

Acknowledgement

Discovered during an independent product security audit commissioned by Fortinet.

Timeline

2026-03-10: Initial publication