PT-2025-50119 · Fortinet · Fortiweb

Published

2025-12-09

·

Updated

2025-12-17

·

CVE-2025-59719

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiWeb versions 7.4.0 through 7.4.9 Fortinet FortiWeb versions 7.6.0 through 7.6.4 Fortinet FortiWeb version 8.0.0
Description An improper verification of cryptographic signature exists that may allow an unauthenticated attacker to bypass FortiCloud SSO login authentication. This is achieved by sending a crafted SAML response message.
Recommendations Fortinet FortiWeb versions 7.4.0 through 7.4.9 should be updated. Fortinet FortiWeb versions 7.6.0 through 7.6.4 should be updated. Fortinet FortiWeb version 8.0.0 should be updated.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-59719

Affected Products

Fortiweb