7.2
CVE-2026-22572
- EPSS 0.09%
- Veröffentlicht 10.03.2026 16:44:16
- Zuletzt bearbeitet 16.03.2026 14:18:11
- Quelle psirt@fortinet.com
- CVE-Watchlists
- Unerledigt
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortianalyzer Version >= 7.2.2 < 7.4.8
Fortinet ≫ Fortianalyzer Version >= 7.6.0 < 7.6.4
Fortinet ≫ Fortimanager Version >= 7.2.2 < 7.4.8
Fortinet ≫ Fortimanager Version >= 7.6.0 < 7.6.4
Fortinet ≫ Fortimanager Cloud Version >= 7.2.2 < 7.4.8
Fortinet ≫ Fortimanager Cloud Version >= 7.6.0 < 7.6.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.246 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@fortinet.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.