An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-647 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Dec 2025, 19:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-647 - Vendor Advisory | |
| First Time |
Fortinet
Fortinet fortiweb |
|
| CPE | cpe:2.3:a:fortinet:fortiweb:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
09 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 18:15
Updated : 2025-12-09 19:59
NVD link : CVE-2025-59719
Mitre link : CVE-2025-59719
CVE.ORG link : CVE-2025-59719
JSON object : View
Products Affected
fortinet
- fortiweb
CWE
CWE-347
Improper Verification of Cryptographic Signature
