Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (CVE-2026-24858)
Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (TL-2026-0003), also tracked as FG-IR-26-060, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-01-27. It has no confirmed attribution, affects Fortinet FortiOS, references 1 CVE (CVE-2026-24858), maps to 28 MITRE ATT&CK techniques (T1005, T1021.001, T1041), and is covered by 15 detection rules and 59 indicators of compromise.
Key facts for TL-2026-0003
- Threat ID
- TL-2026-0003
- Also known as
- FG-IR-26-060, FortiCloud SSO Bypass, Fortinet Auth Bypass
- Severity
- CRITICAL
- CVSS
- 9.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-01-27
- Last reviewed
- 2026-01-27
- Attribution confidence
- NONE
- Motivation
- ESPIONAGE
- Target sectors
- Government, Financial Services, Healthcare, Technology, Critical Infrastructure, Defense, Education, Telecommunications
- Target regions
- Global
- Detection rules
- 15
- Indicators of compromise
- 59
Two critical FortiCloud SSO authentication bypass vulnerabilities (CVE-2025-59718 / FG-IR-25-647 and CVE-2026-24858 / FG-IR-26-060) allow unauthenticated attackers to bypass FortiCloud Single Sign-On authentication on FortiOS, FortiProxy, FortiWeb, FortiManager, FortiAnalyzer, and FortiSwitchManager devices via crafted SAML messages. CVE-2025-59718 (CWE-347, Improper Verification of Cryptographic Signature, published Dec 9 2025) was the initial finding from Fortinet's internal code audit. CVE-2026-24858 (CWE-288, Authentication Bypass Using Alternate Path, published Jan 27 2026) was discovered after patched devices were STILL being exploited — a NEW attack path bypassing the December fix. Both are CRITICAL severity. Active exploitation confirmed: threat actors used malicious FortiCloud accounts (cloud-noc@mail.io, cloud-init@mail.io, heltaylor.12@tutamail.com, support@openmail.pro) to log into victim devices CROSS-TENANT — accessing FortiGate firewalls registered to OTHER organizations' FortiCloud accounts. Post-exploitation: config download + local admin account creation (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount) for persistence. Attacker IPs included Cloudflare-fronted infrastructure. Fortinet emergency response: locked malicious accounts Jan 22, disabled FortiCloud SSO globally Jan 26, restored with version-gating Jan 27. This is a CROSS-TENANT CLOUD SSO attack — the identity layer that was supposed to centralize trust BECAME the universal bypass. Affects potentially hundreds of thousands of FortiGate firewalls worldwide with FortiCloud SSO enabled (auto-enabled upon FortiCare registration unless explicitly disabled).
How Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass works
The FortiCloud SSO authentication bypass represents one of the most dangerous vulnerability classes in modern enterprise security: a CROSS-TENANT identity infrastructure compromise where the centralized authentication system designed to simplify and secure access becomes the universal bypass.
**The Identity Infrastructure — FortiCloud SSO:**
FortiCloud SSO is Fortinet's centralized cloud-based Single Sign-On service that provides: - Administrative authentication to FortiGate firewalls, FortiProxy, FortiWeb WAFs, FortiManager, FortiAnalyzer, and FortiSwitchManager - SAML-based authentication flow — devices trust FortiCloud as the Identity Provider (IdP) - Auto-enabled upon FortiCare device registration unless administrator explicitly disables the toggle - Cross-product authentication — one FortiCloud account manages devices across the Fortinet product portfolio - Deployed across hundreds of thousands of Fortinet devices worldwide in enterprises, government, and critical infrastructure
The critical design assumption: devices TRUST that FortiCloud SSO assertions are valid and that the authenticated user has legitimate access to THAT SPECIFIC device. Both CVEs break this trust.
**CVE-2025-59718 (FG-IR-25-647) — The First Discovery:**
- **Type**: Improper Verification of Cryptographic Signature (CWE-347) - **Severity**: Critical - **Published**: December 9, 2025 - **Discovery**: Internal code audit by Yonghui Han and Theo Leleu of Fortinet Product Security - **Root Cause**: FortiOS, FortiProxy, FortiWeb, and FortiSwitchManager did not properly verify the cryptographic signature of FortiCloud SSO SAML assertions - **Impact**: Unauthenticated attacker can craft SAML messages that bypass SSO authentication - **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiSwitchManager 7.0-7.2, FortiWeb 7.4-8.0 - **Patches**: FortiOS 7.6.4+, FortiProxy 7.6.4+, FortiSwitchManager 7.2.7+, FortiWeb 7.6.5+
**CVE-2026-24858 (FG-IR-26-060) — The Second Attack Path:**
After organizations patched CVE-2025-59718, customers reported that FULLY PATCHED devices were still being compromised via FortiCloud SSO. Fortinet investigated and discovered a SECOND vulnerability — a completely different attack path.
- **Type**: Authentication Bypass Using Alternate Path or Channel (CWE-288) - **Severity**: Critical - **Published**: January 27, 2026 - **Root Cause**: An alternate authentication path existed that bypassed the SSO verification even on patched devices - **Impact**: Attacker with a FortiCloud account can log into devices registered to OTHER FortiCloud accounts — CROSS-TENANT access - **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiManager 7.0-7.6, FortiAnalyzer 7.0-7.6, FortiWeb 7.4-8.0 - **Patches**: FortiOS 7.6.6+, FortiManager 7.6.6+, FortiAnalyzer 7.6.6+, FortiProxy 7.6.6+, FortiWeb 8.0.4+ - **Key difference**: CVE-2026-24858 ALSO affects FortiManager and FortiAnalyzer — extending the blast radius to management and analytics infrastructure
**Active Exploitation — The Cross-Tenant Attack:**
The exploitation pattern is devastating in its simplicity:
1. **Attacker registers a FortiCloud account** — legitimate account creation, no compromise needed 2. **Crafts SAML assertion** targeting other organizations' devices 3. **Bypasses SSO verification** to authenticate as super_admin on VICTIM devices 4. **Downloads device configuration** — containing VPN configurations, firewall rules, network topology, credentials 5. **Creates local admin account** for persistence (audit, backup, itadmin, secadmin, support, etc.) 6. **Attacker retains access** even if FortiCloud SSO is later disabled — the local admin account provides independent access
Observed attacker accounts: - cloud-noc@mail.io - cloud-init@mail.io - heltaylor.12@tutamail.com - support@openmail.pro
Observed attacker IPs (including Cloudflare-fronted): - 104.28.244.115, 104.28.212.114, 104.28.212.115 - 104.28.195.105, 104.28.195.106 - 104.28.227.106, 104.28.227.105 - 104.28.244.114, 104.28.244.116 - 163.61.198.15, 38.54.6.28 - 37.1.209.19, 217.119.139.50
**Fortinet Emergency Response Timeline:**
- Dec 9, 2025: CVE-2025-59718 advisory published - Jan 22, 2026: Fortinet locks malicious FortiCloud accounts being used in active exploitation - Jan 23, 2026: Additional malicious accounts disabled - Jan 26, 2026: Fortinet DISABLES FortiCloud SSO GLOBALLY to stop exploitation - Jan 27, 2026: CVE-2026-24858 advisory published; FortiCloud SSO restored but version-gated — only patched devices can use SSO - Jan 28, 2026: Confirmed third-party SAML IdPs and FortiAuthenticator NOT impacted - Jan 30, 2026: Final patch releases published
The decision to GLOBALLY DISABLE FortiCloud SSO on Jan 26 is extraordinary — Fortinet effectively shut down their own cloud identity service for all customers worldwide to stop an active attack. This demonstrates the severity of cross-tenant SSO compromise.
**The Cross-Tenant SSO Paradigm:**
This is NOT a traditional vulnerability. It's a failure of the IDENTITY TRUST MODEL: - The SAML assertion is the key — whoever can forge or manipulate it has access to ANY device trusting that IdP - Cross-tenant means the attacker doesn't need to compromise the victim's account — they use their OWN account to access the victim's devices - Auto-enablement means most FortiGate deployments have SSO enabled without the administrator's conscious decision - The attacker gets super_admin — the highest privilege level, full configuration access - Post-exploitation local account creation survives SSO disablement — the persistence outlives the vulnerability fix
MITRE ATT&CK techniques used in TL-2026-0003
collection
T1005 Data from Local System; T1213 Data from Information Repositories; T1602.002 Network Device Configuration Dump
lateral-movement
T1021.001 Remote Desktop Protocol; T1550 Use Alternate Authentication Material; T1550.001 Application Access Token
exfiltration
T1041 Exfiltration Over C2 Channel
discovery
T1046 Network Service Discovery; T1082 System Information Discovery
execution
T1059 Command and Scripting Interpreter
defense-evasion
T1078 Valid Accounts; T1078.004 Cloud Accounts; T1684.001 Impersonation
persistence
T1098 Account Manipulation; T1133 External Remote Services; T1136 Create Account; T1136.001 Local Account
initial-access
T1190 Exploit Public-Facing Application; T1199 Trusted Relationship
credential-access
T1552 Unsecured Credentials; T1552.001 Credentials In Files; T1556 Modify Authentication Process; T1606 Forge Web Credentials
resource-development
T1585 Establish Accounts; T1587 Develop Capabilities; T1588.002 Tool
reconnaissance
T1595 Active Scanning; T1596 Search Open Technical Databases
Affected products and versions in Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
- Fortinet — FortiOS
Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.10; 7.2.0-7.2.12; 7.0.0-7.0.18
Fixed in: 7.6.6+; 7.4.11+; 7.2.13 (upcoming); 7.0.19 (upcoming) - Fortinet — FortiManager
Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.9; 7.2.0-7.2.11; 7.0.0-7.0.15
Fixed in: 7.6.6+; 7.4.10+; 7.2.12 (upcoming); 7.0.16 (upcoming) - Fortinet — FortiAnalyzer
Vulnerable versions: 7.6.0-7.6.5; 7.4.0-7.4.9; 7.2.0-7.2.11; 7.0.0-7.0.15
Fixed in: 7.6.6+; 7.4.10+; 7.2.12 (upcoming); 7.0.16 (upcoming) - Fortinet — FortiProxy
Vulnerable versions: 7.6.0-7.6.4; 7.4.0-7.4.12; 7.2.0-7.2.15; 7.0.0-7.0.22
Fixed in: 7.6.6 (upcoming); 7.4.13 (upcoming); 7.2.16 (upcoming); 7.0.23 (upcoming) - Fortinet — FortiWeb
Vulnerable versions: 8.0.0-8.0.3; 7.6.0-7.6.6; 7.4.0-7.4.11
Fixed in: 8.0.4 (upcoming); 7.6.7 (upcoming); 7.4.12 (upcoming)
Remediation for Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
Patches
- [object Object]
Immediate actions
- FortiCloud SSO is now server-side blocked for vulnerable firmware — verify your devices are on fixed versions
- Disable FortiCloud SSO locally: config system global / set admin-forticloud-sso-login disable / end
- Review all admin accounts for unauthorized entries (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount)
- Check FortiOS event logs for SSO logins from IOC email addresses and IP addresses
- If IOCs detected: treat device as fully compromised — restore from known-clean backup, rotate ALL credentials including LDAP/AD
Workarounds
- FortiCloud server-side block on vulnerable firmware (automatic)
- Disable FortiCloud SSO via CLI
- FortiManager/FortiAnalyzer: config system saml / set forticloud-sso disable / end
- Restrict management interface access via local-in policy
Longer-term hardening
- Upgrade to fixed firmware (FortiOS 7.6.6/7.4.11, FortiManager 7.6.6/7.4.10, FortiAnalyzer 7.6.6/7.4.10)
- Never expose FortiGate management interfaces to the internet
- Implement network segmentation to limit blast radius of firewall compromise
- Monitor for new/modified admin accounts as a standing detection rule
- Rotate all hashed credentials from exfiltrated config files — assume offline cracking
CVEs associated with Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
Weaknesses (CWE) in Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
CWE-288
Timeline of Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
- Fortinet publishes advisory FG-IR-25-647 for CVE-2025-59718 (CVSS Critical) — Improper Verification of Cryptographic Signature (CWE-347) in FortiCloud SSO. Discovered internally by Yonghui Han and Theo Leleu of Fortinet Product Security during code audit. Affects FortiOS, FortiProxy, FortiSwitchManager, FortiWeb. Unauthenticated attacker can bypass FortiCloud SSO via crafted SAML message. Patches released. Source: https://www.fortiguard.com/psirt/FG-IR-25-647
- Fortinet detects active exploitation of FortiCloud SSO bypass against customer devices. Customers report unexpected login activity. Malicious FortiCloud accounts cloud-noc@mail.io and cloud-init@mail.io identified. Fortinet locks the malicious accounts. Critically: exploitation observed on FULLY PATCHED devices — indicating a NEW attack path beyond CVE-2025-59718. Source: https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios
- Fortinet disables additional FortiCloud accounts being abused in the cross-tenant SSO attack. Additional malicious accounts identified: heltaylor.12@tutamail.com, support@openmail.pro. Post-exploitation pattern confirmed: config download + local admin account creation (audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system, adccount).
- EMERGENCY RESPONSE: Fortinet GLOBALLY DISABLES FortiCloud SSO for ALL customers worldwide to stop active cross-tenant exploitation. This extraordinary measure — shutting down their own cloud identity service — demonstrates the severity: they could not stop the attack by blocking individual accounts because the PROTOCOL was the vulnerability. All FortiGate/FortiProxy/FortiWeb/FortiManager/FortiAnalyzer devices lose FortiCloud SSO capability.
- Fortinet publishes advisory FG-IR-26-060 for CVE-2026-24858 (CVSS Critical) — Authentication Bypass Using Alternate Path or Channel (CWE-288). The SECOND FortiCloud SSO bypass vulnerability — a different attack path that bypassed the December patch. Affects FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiWeb (expanded scope — FortiManager and FortiAnalyzer now affected). FortiCloud SSO restored with VERSION GATING: only patched devices can use SSO. Source: https://www.fortiguard.com/psirt/FG-IR-26-060
- Fortinet confirms that third-party SAML Identity Providers and FortiAuthenticator are NOT affected by either CVE. The vulnerability is specific to FortiCloud SSO — organizations using external IdPs or FortiAuthenticator for SSO are safe. This narrows the impact to organizations relying specifically on Fortinet's cloud SSO service.
- Fortinet publishes final patch releases for CVE-2026-24858 across all affected product lines. Upgrade matrix finalized. FortiCloud SSO continues operating with version gating — vulnerable device versions blocked from SSO authentication at the server side. Organizations must upgrade to restore SSO functionality.
- Fortinet publishes additional February 2026 security advisories including CVE-2026-22153 (LDAP auth bypass in FortiOS), CVE-2025-55018 (HTTP request smuggling), CVE-2025-68686 (SSL-VPN symlink persistence patch bypass), CVE-2025-62439 (firewall policy bypass in FSSO). The volume of concurrent critical vulnerabilities compounds the patching burden for Fortinet customers. Source: https://www.fortiguard.com/psirt
- As of 2026-05-29, CVE-2026-24858 (FortiCloud SSO bypass) is in CISA KEV but fully remediated: Fortinet shipped fixes (FortiOS 7.4.11+) and enforces a server-side version-gate blocking SSO from vulnerable devices. Arctic Wolf reports no new exploitation since January, malicious accounts were locked Jan 22, and Shadowserver-exposed instances fell below 10,000 from 26,000+.
Sources cited for Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
Threats related to Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass
Detection coverage for TL-2026-0003
As of 2026-01-27, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0003 across Splunk SPL, Microsoft KQL and Sigma, covering 59 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.