Description
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
In plain language
AI Act nowFortinet FortiManager and FortiManager Cloud have an authentication-bypass bug in specific older versions that could let an attacker get in without logging in; if you run these versions, you should act now.
Unauthenticated authentication bypass (CWE-288) in Fortinet FortiManager and FortiManager Cloud via an alternate path or channel, allowing a remote attacker to improperly access the system without credentials on affected versions.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-70468 and every CVE in our database. Create a free account — no credit card required.
Create Free Account