FortiOS, FortiWeb, and FortiProxy Vulnerability Lets Attackers Bypass FortiCloud SSO Authentication
## Cybersecurity: Fortinet Security Advisory
Cybersecurity: Fortinet Security Advisory
Fortinet has released a security advisory concerning a critical vulnerability affecting its FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager product lines. This vulnerability, identified as an Improper Verification of Cryptographic Signature (CWE-347), allows an unauthenticated attacker to bypass FortiCloud Single Sign-On (SSO) login authentication.
The issue arises from the device's failure to correctly verify signatures within SAML messages. Exploitation could enable unauthorized administrative access through a crafted SAML message. This vulnerability was internally discovered by Fortinet Product Security team members Yonghui Han and Theo Leleu and publicly disclosed on Tue, Dec 9, 2025.
Though the FortiCloud SSO login feature is disabled by default, it remains a significant vulnerability in operational environments. When a device is registered to FortiCare via the graphical user interface (GUI), the "Allow administrative login using FortiCloud SSO" toggle is enabled by default. Unless explicitly disabled by the administrator, the device becomes susceptible to this bypass immediately.
The issue arises from the device's failure to correctly verify signatures within SAML messages.
Fortinet advises customers to upgrade to the latest versions listed below. For organizations unable to patch immediately, a temporary workaround is available: disabling the FortiCloud login feature.
Product Affected Versions Remediation
FortiOS 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above FortiOS 7.4 7.4.0 through 7.4.8 Upgrade to 7.4.9 or above FortiOS 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above FortiOS 7.0 7.0.0 through 7.0.17 Upgrade to 7.0.18 or above FortiOS 6.4 Not affected None FortiProxy 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above FortiProxy 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above FortiProxy 7.2 7.2.0 through 7.2.14 Upgrade to 7.2.15 or above FortiProxy 7.0 7.0.0 through 7.0.21 Upgrade to 7.0.22 or above FortiSwitchManager 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above FortiSwitchManager 7.0 7.0.0 through 7.0.5 Upgrade to 7.0.6 or above FortiWeb 8.0 8.0.0 Upgrade to 8.0.1 or above FortiWeb 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above FortiWeb 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above
Based on reporting by Cyber Security News.
