Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (CVE-2026-24858)

Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (TL-2026-0003), also tracked as FG-IR-26-060, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-01-27. It has no confirmed attribution, affects Fortinet FortiOS, references 1 CVE (CVE-2026-24858), maps to 28 MITRE ATT&CK techniques (T1005, T1021.001, T1041), and is covered by 15 detection rules and 59 indicators of compromise.

Key facts for TL-2026-0003

Threat ID
TL-2026-0003
Also known as
FG-IR-26-060, FortiCloud SSO Bypass, Fortinet Auth Bypass
Severity
CRITICAL
CVSS
9.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N)
Status
PATCHED
Category
VULNERABILITY
First published
2026-01-27
Last reviewed
2026-01-27
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
Government, Financial Services, Healthcare, Technology, Critical Infrastructure, Defense, Education, Telecommunications
Target regions
Global
Detection rules
15
Indicators of compromise
59

Two critical FortiCloud SSO authentication bypass vulnerabilities (CVE-2025-59718 / FG-IR-25-647 and CVE-2026-24858 / FG-IR-26-060) allow unauthenticated attackers to bypass FortiCloud Single Sign-On authentication on FortiOS, FortiProxy, FortiWeb, FortiManager, FortiAnalyzer, and FortiSwitchManager devices via crafted SAML messages. CVE-2025-59718 (CWE-347, Improper Verification of Cryptographic Signature, published Dec 9 2025) was the initial finding from Fortinet's internal code audit. CVE-2026-24858 (CWE-288, Authentication Bypass Using Alternate Path, published Jan 27 2026) was discovered after patched devices were STILL being exploited — a NEW attack path bypassing the December fix. Both are CRITICAL severity. Active exploitation confirmed: threat actors used malicious FortiCloud accounts (cloud-noc@mail.io, cloud-init@mail.io, heltaylor.12@tutamail.com, support@openmail.pro) to log into victim devices CROSS-TENANT — accessing FortiGate firewalls registered to OTHER organizations' FortiCloud accounts. Post-exploitation: config download + local admin account creation (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount) for persistence. Attacker IPs included Cloudflare-fronted infrastructure. Fortinet emergency response: locked malicious accounts Jan 22, disabled FortiCloud SSO globally Jan 26, restored with version-gating Jan 27. This is a CROSS-TENANT CLOUD SSO attack — the identity layer that was supposed to centralize trust BECAME the universal bypass. Affects potentially hundreds of thousands of FortiGate firewalls worldwide with FortiCloud SSO enabled (auto-enabled upon FortiCare registration unless explicitly disabled).

How Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass works

The FortiCloud SSO authentication bypass represents one of the most dangerous vulnerability classes in modern enterprise security: a CROSS-TENANT identity infrastructure compromise where the centralized authentication system designed to simplify and secure access becomes the universal bypass.

**The Identity Infrastructure — FortiCloud SSO:**

FortiCloud SSO is Fortinet's centralized cloud-based Single Sign-On service that provides: - Administrative authentication to FortiGate firewalls, FortiProxy, FortiWeb WAFs, FortiManager, FortiAnalyzer, and FortiSwitchManager - SAML-based authentication flow — devices trust FortiCloud as the Identity Provider (IdP) - Auto-enabled upon FortiCare device registration unless administrator explicitly disables the toggle - Cross-product authentication — one FortiCloud account manages devices across the Fortinet product portfolio - Deployed across hundreds of thousands of Fortinet devices worldwide in enterprises, government, and critical infrastructure

The critical design assumption: devices TRUST that FortiCloud SSO assertions are valid and that the authenticated user has legitimate access to THAT SPECIFIC device. Both CVEs break this trust.

**CVE-2025-59718 (FG-IR-25-647) — The First Discovery:**

- **Type**: Improper Verification of Cryptographic Signature (CWE-347) - **Severity**: Critical - **Published**: December 9, 2025 - **Discovery**: Internal code audit by Yonghui Han and Theo Leleu of Fortinet Product Security - **Root Cause**: FortiOS, FortiProxy, FortiWeb, and FortiSwitchManager did not properly verify the cryptographic signature of FortiCloud SSO SAML assertions - **Impact**: Unauthenticated attacker can craft SAML messages that bypass SSO authentication - **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiSwitchManager 7.0-7.2, FortiWeb 7.4-8.0 - **Patches**: FortiOS 7.6.4+, FortiProxy 7.6.4+, FortiSwitchManager 7.2.7+, FortiWeb 7.6.5+

**CVE-2026-24858 (FG-IR-26-060) — The Second Attack Path:**

After organizations patched CVE-2025-59718, customers reported that FULLY PATCHED devices were still being compromised via FortiCloud SSO. Fortinet investigated and discovered a SECOND vulnerability — a completely different attack path.

- **Type**: Authentication Bypass Using Alternate Path or Channel (CWE-288) - **Severity**: Critical - **Published**: January 27, 2026 - **Root Cause**: An alternate authentication path existed that bypassed the SSO verification even on patched devices - **Impact**: Attacker with a FortiCloud account can log into devices registered to OTHER FortiCloud accounts — CROSS-TENANT access - **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiManager 7.0-7.6, FortiAnalyzer 7.0-7.6, FortiWeb 7.4-8.0 - **Patches**: FortiOS 7.6.6+, FortiManager 7.6.6+, FortiAnalyzer 7.6.6+, FortiProxy 7.6.6+, FortiWeb 8.0.4+ - **Key difference**: CVE-2026-24858 ALSO affects FortiManager and FortiAnalyzer — extending the blast radius to management and analytics infrastructure

**Active Exploitation — The Cross-Tenant Attack:**

The exploitation pattern is devastating in its simplicity:

1. **Attacker registers a FortiCloud account** — legitimate account creation, no compromise needed 2. **Crafts SAML assertion** targeting other organizations' devices 3. **Bypasses SSO verification** to authenticate as super_admin on VICTIM devices 4. **Downloads device configuration** — containing VPN configurations, firewall rules, network topology, credentials 5. **Creates local admin account** for persistence (audit, backup, itadmin, secadmin, support, etc.) 6. **Attacker retains access** even if FortiCloud SSO is later disabled — the local admin account provides independent access

Observed attacker accounts: - cloud-noc@mail.io - cloud-init@mail.io - heltaylor.12@tutamail.com - support@openmail.pro

Observed attacker IPs (including Cloudflare-fronted): - 104.28.244.115, 104.28.212.114, 104.28.212.115 - 104.28.195.105, 104.28.195.106 - 104.28.227.106, 104.28.227.105 - 104.28.244.114, 104.28.244.116 - 163.61.198.15, 38.54.6.28 - 37.1.209.19, 217.119.139.50

**Fortinet Emergency Response Timeline:**

- Dec 9, 2025: CVE-2025-59718 advisory published - Jan 22, 2026: Fortinet locks malicious FortiCloud accounts being used in active exploitation - Jan 23, 2026: Additional malicious accounts disabled - Jan 26, 2026: Fortinet DISABLES FortiCloud SSO GLOBALLY to stop exploitation - Jan 27, 2026: CVE-2026-24858 advisory published; FortiCloud SSO restored but version-gated — only patched devices can use SSO - Jan 28, 2026: Confirmed third-party SAML IdPs and FortiAuthenticator NOT impacted - Jan 30, 2026: Final patch releases published

The decision to GLOBALLY DISABLE FortiCloud SSO on Jan 26 is extraordinary — Fortinet effectively shut down their own cloud identity service for all customers worldwide to stop an active attack. This demonstrates the severity of cross-tenant SSO compromise.

**The Cross-Tenant SSO Paradigm:**

This is NOT a traditional vulnerability. It's a failure of the IDENTITY TRUST MODEL: - The SAML assertion is the key — whoever can forge or manipulate it has access to ANY device trusting that IdP - Cross-tenant means the attacker doesn't need to compromise the victim's account — they use their OWN account to access the victim's devices - Auto-enablement means most FortiGate deployments have SSO enabled without the administrator's conscious decision - The attacker gets super_admin — the highest privilege level, full configuration access - Post-exploitation local account creation survives SSO disablement — the persistence outlives the vulnerability fix

MITRE ATT&CK techniques used in TL-2026-0003

collection

T1005 Data from Local System; T1213 Data from Information Repositories; T1602.002 Network Device Configuration Dump

lateral-movement

T1021.001 Remote Desktop Protocol; T1550 Use Alternate Authentication Material; T1550.001 Application Access Token

exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery; T1082 System Information Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1078 Valid Accounts; T1078.004 Cloud Accounts; T1684.001 Impersonation

persistence

T1098 Account Manipulation; T1133 External Remote Services; T1136 Create Account; T1136.001 Local Account

initial-access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

credential-access

T1552 Unsecured Credentials; T1552.001 Credentials In Files; T1556 Modify Authentication Process; T1606 Forge Web Credentials

resource-development

T1585 Establish Accounts; T1587 Develop Capabilities; T1588.002 Tool

reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

  • Fortinet — FortiOS
    Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.10; 7.2.0-7.2.12; 7.0.0-7.0.18
    Fixed in: 7.6.6+; 7.4.11+; 7.2.13 (upcoming); 7.0.19 (upcoming)
  • Fortinet — FortiManager
    Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.9; 7.2.0-7.2.11; 7.0.0-7.0.15
    Fixed in: 7.6.6+; 7.4.10+; 7.2.12 (upcoming); 7.0.16 (upcoming)
  • Fortinet — FortiAnalyzer
    Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.9; 7.2.0-7.2.11; 7.0.0-7.0.15
    Fixed in: 7.6.6+; 7.4.10+; 7.2.12 (upcoming); 7.0.16 (upcoming)
  • Fortinet — FortiProxy
    Vulnerable versions: 7.6.0-7.6.4; 7.4.0-7.4.12; 7.2.0-7.2.15; 7.0.0-7.0.22
    Fixed in: 7.6.6 (upcoming); 7.4.13 (upcoming); 7.2.16 (upcoming); 7.0.23 (upcoming)
  • Fortinet — FortiWeb
    Vulnerable versions: 8.0.0-8.0.3; 7.6.0-7.6.6; 7.4.0-7.4.11
    Fixed in: 8.0.4 (upcoming); 7.6.7 (upcoming); 7.4.12 (upcoming)

Remediation for Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

Patches

  • [object Object]

Immediate actions

  • FortiCloud SSO is now server-side blocked for vulnerable firmware — verify your devices are on fixed versions
  • Disable FortiCloud SSO locally: config system global / set admin-forticloud-sso-login disable / end
  • Review all admin accounts for unauthorized entries (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount)
  • Check FortiOS event logs for SSO logins from IOC email addresses and IP addresses
  • If IOCs detected: treat device as fully compromised — restore from known-clean backup, rotate ALL credentials including LDAP/AD

Workarounds

  • FortiCloud server-side block on vulnerable firmware (automatic)
  • Disable FortiCloud SSO via CLI
  • FortiManager/FortiAnalyzer: config system saml / set forticloud-sso disable / end
  • Restrict management interface access via local-in policy

Longer-term hardening

  • Upgrade to fixed firmware (FortiOS 7.6.6/7.4.11, FortiManager 7.6.6/7.4.10, FortiAnalyzer 7.6.6/7.4.10)
  • Never expose FortiGate management interfaces to the internet
  • Implement network segmentation to limit blast radius of firewall compromise
  • Monitor for new/modified admin accounts as a standing detection rule
  • Rotate all hashed credentials from exfiltrated config files — assume offline cracking

CVEs associated with Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

CVE-2026-24858

Weaknesses (CWE) in Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

CWE-288

Timeline of Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

  • Fortinet publishes advisory FG-IR-25-647 for CVE-2025-59718 (CVSS Critical) — Improper Verification of Cryptographic Signature (CWE-347) in FortiCloud SSO. Discovered internally by Yonghui Han and Theo Leleu of Fortinet Product Security during code audit. Affects FortiOS, FortiProxy, FortiSwitchManager, FortiWeb. Unauthenticated attacker can bypass FortiCloud SSO via crafted SAML message. Patches released. Source: https://www.fortiguard.com/psirt/FG-IR-25-647
  • Fortinet detects active exploitation of FortiCloud SSO bypass against customer devices. Customers report unexpected login activity. Malicious FortiCloud accounts cloud-noc@mail.io and cloud-init@mail.io identified. Fortinet locks the malicious accounts. Critically: exploitation observed on FULLY PATCHED devices — indicating a NEW attack path beyond CVE-2025-59718. Source: https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios
  • Fortinet disables additional FortiCloud accounts being abused in the cross-tenant SSO attack. Additional malicious accounts identified: heltaylor.12@tutamail.com, support@openmail.pro. Post-exploitation pattern confirmed: config download + local admin account creation (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount).
  • EMERGENCY RESPONSE: Fortinet GLOBALLY DISABLES FortiCloud SSO for ALL customers worldwide to stop active cross-tenant exploitation. This extraordinary measure — shutting down their own cloud identity service — demonstrates the severity: they could not stop the attack by blocking individual accounts because the PROTOCOL was the vulnerability. All FortiGate/FortiProxy/FortiWeb/FortiManager/FortiAnalyzer devices lose FortiCloud SSO capability.
  • Fortinet publishes advisory FG-IR-26-060 for CVE-2026-24858 (CVSS Critical) — Authentication Bypass Using Alternate Path or Channel (CWE-288). The SECOND FortiCloud SSO bypass vulnerability — a different attack path that bypassed the December patch. Affects FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiWeb (expanded scope — FortiManager and FortiAnalyzer now affected). FortiCloud SSO restored with VERSION GATING: only patched devices can use SSO. Source: https://www.fortiguard.com/psirt/FG-IR-26-060
  • Fortinet confirms that third-party SAML Identity Providers and FortiAuthenticator are NOT affected by either CVE. The vulnerability is specific to FortiCloud SSO — organizations using external IdPs or FortiAuthenticator for SSO are safe. This narrows the impact to organizations relying specifically on Fortinet's cloud SSO service.
  • Fortinet publishes final patch releases for CVE-2026-24858 across all affected product lines. Upgrade matrix finalized. FortiCloud SSO continues operating with version gating — vulnerable device versions blocked from SSO authentication at the server side. Organizations must upgrade to restore SSO functionality.
  • Fortinet publishes additional February 2026 security advisories including CVE-2026-22153 (LDAP auth bypass in FortiOS), CVE-2025-55018 (HTTP request smuggling), CVE-2025-68686 (SSL-VPN symlink persistence patch bypass), CVE-2025-62439 (firewall policy bypass in FSSO). The volume of concurrent critical vulnerabilities compounds the patching burden for Fortinet customers. Source: https://www.fortiguard.com/psirt
  • As of 2026-05-29, CVE-2026-24858 (FortiCloud SSO bypass) is in CISA KEV but fully remediated: Fortinet shipped fixes (FortiOS 7.4.11+) and enforces a server-side version-gate blocking SSO from vulnerable devices. Arctic Wolf reports no new exploitation since January, malicious accounts were locked Jan 22, and Shadowserver-exposed instances fell below 10,000 from 26,000+.

Sources cited for Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

Threats related to Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass

Detection coverage for TL-2026-0003

As of 2026-01-27, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0003 across Splunk SPL, Microsoft KQL and Sigma, covering 59 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats