Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (CVE-2026-24858) — Threadlinqs Intelligence
As of 2026-05-30, Fortinet FortiCloud SSO Cross-Tenant Authentication Bypass (CVE-2026-24858) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 15 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 59 indicators of compromise.
Threat ID: TL-2026-0003 · Severity: CRITICAL · CVSS: 9.4 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · ESPIONAGE
Two critical FortiCloud SSO authentication bypass vulnerabilities (CVE-2025-59718 / FG-IR-25-647 and CVE-2026-24858 / FG-IR-26-060) allow unauthenticated attackers to bypass FortiCloud Single Sign-On
The FortiCloud SSO authentication bypass represents one of the most dangerous vulnerability classes in modern enterprise security: a CROSS-TENANT identity infrastructure compromise where the centralized authentication system designed to simplify and secure access becomes the universal bypass.
**The Identity Infrastructure — FortiCloud SSO:**
FortiCloud SSO is Fortinet's centralized cloud-based Single Sign-On service that provides:
- Administrative authentication to FortiGate firewalls, FortiProxy, FortiWeb WAFs, FortiManager, FortiAnalyzer, and FortiSwitchManager
- SAML-based authentication flow — devices trust FortiCloud as the Identity Provider (IdP)
- Auto-enabled upon FortiCare device registration unless administrator explicitly disables the toggle
- Cross-product authentication — one FortiCloud account manages devices across the Fortinet product portfolio
- Deployed across hundreds of thousands of Fortinet devices worldwide in enterprises, government, and critical infrastructure
The critical design assumption: devices TRUST that FortiCloud SSO assertions are valid and that the authenticated user has legitimate access to THAT SPECIFIC device. Both CVEs break this trust.
**CVE-2025-59718 (FG-IR-25-647) — The First Discovery:**
- **Type**: Improper Verification of Cryptographic Signature (CWE-347)
- **Severity**: Critical
- **Published**: December 9, 2025
- **Discovery**: Internal code audit by Yonghui Han and Theo Leleu of Fortinet Product Security
- **Root Cause**: FortiOS, FortiProxy, FortiWeb, and FortiSwitchManager did not properly verify the cryptographic signature of FortiCloud SSO SAML assertions
- **Impact**: Unauthenticated attacker can craft SAML messages that bypass SSO authentication
- **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiSwitchManager 7.0-7.2, FortiWeb 7.4-8.0
- **Patches**: FortiOS 7.6.4+, FortiProxy 7.6.4+, FortiSwitchManager 7.2.7+, FortiWeb 7.6.5+
**CVE-2026-24858 (FG-IR-26-060) — The Second Attack Path:**
After organizations patched CVE-2025-59718, customers reported that FULLY PATCHED devices were still being compromised via FortiCloud SSO. Fortinet investigated and discovered a SECOND vulnerability — a completely different attack path.
- **Type**: Authentication Bypass Using Alternate Path or Channel (CWE-288)
- **Severity**: Critical
- **Published**: January 27, 2026
- **Root Cause**: An alternate authentication path existed that bypassed the SSO verification even on patched devices
- **Impact**: Attacker with a FortiCloud account can log into devices registered to OTHER FortiCloud accounts — CROSS-TENANT access
- **Affected**: FortiOS 7.0-7.6, FortiProxy 7.0-7.6, FortiManager 7.0-7.6, FortiAnalyzer 7.0-7.6, FortiWeb 7.4-8.0
- **Patches**: FortiOS 7.6.6+, FortiManager 7.6.6+, FortiAnalyzer 7.6.6+, FortiProxy 7.6.6+, FortiWeb 8.0.4+
- **Key difference**: CVE-2026-24858 ALSO affects FortiManager and FortiAnalyzer — extending the blast radius to management and analytics infrastructure
**Active Exploitation — The Cross-Tenant Attack:**
The exploitation pattern is devastating in its simplicity:
1. **Attacker registers a FortiCloud account** — legitimate account creation, no compromise needed
2. **Crafts SAML assertion** targeting other organizations' devices
3. **Bypasses SSO verification** to authenticate as super_admin on VICTIM devices
4. **Downloads device configuration** — containing VPN configurations, firewall rules, network topology, credentials
5. **Creates local admin account** for persistence (audit, backup, itadmin, secadmin, support, etc.)
6. **Attacker retains access** even if FortiCloud SSO is later disabled — the local admin account provides independent access
Observed attacker accounts:
- cloud-noc@mail.io
- cloud-init@mail.io
- heltaylor.12@tutamail.com
- support@openmail.pro
Observed attacker IPs (including Cloudflare-fronted):
- 104.28.244.115, 104.28.212.114, 104.28.212.115
- 104.28.195.105, 104.28.195.106
- 104.28.227.106, 104.28.227.105
- 104.28.244.114,
Target sectors: Government, Financial Services, Healthcare, Technology, Critical Infrastructure, Defense, Education, Telecommunications
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 15 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 59 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-24858, T1078.004, T1190, T1136.001, T1098, T1552.001, T1602.002, T1550.001, T1021.001, T1041, T1046