PT-2026-7281 · Fortinet · Fortios

CVE-2026-22153

·

Publicado

2026-02-10

·

Atualizado

2026-03-15

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 7.6.0 through 7.6.4
Description An authentication bypass issue exists in Fortinet FortiOS. This flaw may allow an unauthenticated attacker to bypass LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies when the remote LDAP server is configured in a specific way. The issue is due to improper handling of LDAP authentication requests and requires LDAP server configurations that enable unauthenticated binds. An attacker could exploit this to gain unauthorized access without valid credentials. The vulnerable component is the fnbamd daemon.
Recommendations Fortinet FortiOS version 7.6.5 and later are not affected. Upgrade to FortiOS version 7.6.5 or a later version. Disable anonymous or unauthenticated LDAP binds to prevent unauthorized network access via SSL-VPN policy controls.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01821
CVE-2026-22153

Produtos afetados

Fortios