An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-090 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Mar 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests. |
13 Mar 2026, 16:07
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortimanager
Fortinet Fortinet fortianalyzer Fortinet fortimanager Cloud |
|
| Summary |
|
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-090 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
12 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11, FortiManager Cloud 7.6.0 through 7.6.3, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2.2 through 7.2.10 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests. |
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-10 18:18
Updated : 2026-03-16 14:18
NVD link : CVE-2026-22572
Mitre link : CVE-2026-22572
CVE.ORG link : CVE-2026-22572
JSON object : View
Products Affected
fortinet
- fortimanager
- fortimanager_cloud
- fortianalyzer
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
