<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>2FA request can be replayed without a valid token after one successful request</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-26-101</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2026-04-14T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2026-04-14T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2026-04-14T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An Improper authentication vulnerability [CWE-287] in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Escalation of privilege
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            None
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Leslie Zhou of Fortinet PSIRT team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiSOAR PaaS" Type="Product Name">
                <Branch Name="7.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.6.3">FortiSOAR PaaS 7.6.3</FullProductName>
                </Branch>
                <Branch Name="7.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.6.2">FortiSOAR PaaS 7.6.2</FullProductName>
                </Branch>
                <Branch Name="7.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.6.1">FortiSOAR PaaS 7.6.1</FullProductName>
                </Branch>
                <Branch Name="7.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.6.0">FortiSOAR PaaS 7.6.0</FullProductName>
                </Branch>
                <Branch Name="7.5.2" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.5.2">FortiSOAR PaaS 7.5.2</FullProductName>
                </Branch>
                <Branch Name="7.5.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.5.1">FortiSOAR PaaS 7.5.1</FullProductName>
                </Branch>
                <Branch Name="7.5.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR PaaS-7.5.0">FortiSOAR PaaS 7.5.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiSOAR on-premise" Type="Product Name">
                <Branch Name="7.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.6.3">FortiSOAR on-premise 7.6.3</FullProductName>
                </Branch>
                <Branch Name="7.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.6.2">FortiSOAR on-premise 7.6.2</FullProductName>
                </Branch>
                <Branch Name="7.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.6.1">FortiSOAR on-premise 7.6.1</FullProductName>
                </Branch>
                <Branch Name="7.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.6.0">FortiSOAR on-premise 7.6.0</FullProductName>
                </Branch>
                <Branch Name="7.5.2" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.5.2">FortiSOAR on-premise 7.5.2</FullProductName>
                </Branch>
                <Branch Name="7.5.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.5.1">FortiSOAR on-premise 7.5.1</FullProductName>
                </Branch>
                <Branch Name="7.5.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.5.0">FortiSOAR on-premise 7.5.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>2FA request can be replayed without a valid token after one successful request</Title>
        <cvrf:CVE>CVE-2026-23708</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiSOAR PaaS-7.6.3</ProductID>
                <ProductID>FortiSOAR PaaS-7.6.2</ProductID>
                <ProductID>FortiSOAR PaaS-7.6.1</ProductID>
                <ProductID>FortiSOAR PaaS-7.6.0</ProductID>
                <ProductID>FortiSOAR PaaS-7.5.2</ProductID>
                <ProductID>FortiSOAR PaaS-7.5.1</ProductID>
                <ProductID>FortiSOAR PaaS-7.5.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.6.3</ProductID>
                <ProductID>FortiSOAR on-premise-7.6.2</ProductID>
                <ProductID>FortiSOAR on-premise-7.6.1</ProductID>
                <ProductID>FortiSOAR on-premise-7.6.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.5.2</ProductID>
                <ProductID>FortiSOAR on-premise-7.5.1</ProductID>
                <ProductID>FortiSOAR on-premise-7.5.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.7</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-26-101</URL>
                <Description>2FA request can be replayed without a valid token after one successful request</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>