PT-2026-32670 · Fortinet · Fortisoar

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-23708

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiSOAR PaaS versions 7.6.0 through 7.6.3 FortiSOAR PaaS versions 7.5.0 through 7.5.2 FortiSOAR on-premise versions 7.6.0 through 7.6.3 FortiSOAR on-premise versions 7.5.0 through 7.5.2
Description An improper authentication issue exists where an unauthenticated attacker can bypass authentication by replaying a captured 2FA request. This requires the attacker to intercept and decrypt authentication traffic and execute the replay with precise timing before the token expires.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-05564
CVE-2026-23708

Affected Products

Fortisoar