Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/m0d0ri205/cve-2026-24858
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingThreat IntelligenceAuthenticationIncident Response
GitHubm0d0ri205/cve-2026-24858

CVE-2026-24858

Detailed analysis of Fortinet FortiCloud SSO authentication bypass (CVE-2026-24858) including technical breakdown, attack scenarios, detection methods, and mitigation guidance.

View Repository
138 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-24858 Vulnerability Analysis Report (Full Version with Sources)

Fortinet FortiCloud SSO Authentication Bypass Vulnerability

Document Version: 2.0 (Full Source Attribution Version)
Last Updated: January 29, 2026
Purpose: Security Audit, Technical Documentation, Incident Response


📋 Table of Contents

  1. Overview and Basic Information
  2. Detailed Vulnerability Mechanism Analysis
  3. Affected Products and Versions
  4. CVSS Score and Severity Assessment
  5. Real-World Attack Scenarios and Campaigns
  6. Detection and Forensic Indicators (IOCs)
  7. Immediate Response Measures
  8. Security Hardening Recommendations
  9. References and Sources

📋 Overview and Basic Information

1.1 Vulnerability Summary

CVE-2026-24858 is an authentication bypass vulnerability discovered in the FortiCloud SSO (Single Sign-On) authentication mechanism of the Fortinet product family. Exploiting this vulnerability allows a remote attacker to gain access to the system with administrator privileges without authentication.

[Source: NVD - National Vulnerability Database]
https://nvd.nist.gov/vuln/detail/CVE-2026-24858

[Source: Fortinet PSIRT Advisory FG-IR-26-060]
https://www.fortiguard.com/psirt/FG-IR-26-060

1.2 Basic Information Table

ItemDetailsSource
CVE IDCVE-2026-24858NVD
Vulnerability TypeAuthentication Bypass via FortiCloud SSOFortinet PSIRT
CWE ClassificationCWE-288: Authentication Bypass Using an Alternate Path or ChannelNVD
CVSS v3.1 Score9.8 (Critical)NVD
Attack VectorNetwork (Remote)NVD
Attack ComplexityLowNVD
Privileges RequiredNoneNVD
User InteractionNoneNVD
Current StatusActively exploited in the wild (In-the-Wild)SecurityWeek, Arctic Wolf
Affected ProductsFortiOS, FortiProxy, FortiPAM, FortiSwitchManagerFortinet PSIRT
Exposed Systems1,100,000+ (Based on FOFA search)FOFA
Initial Discovery DateEarly January 2026SecurityWeek
Patch Release DateMid-January 2026Fortinet PSIRT

[Source: FOFA Search Engine]
https://en.fofa.info/result?qbase64=YXBwPSJGT1JUSU5FVC1Gb3J0aU1hbmFnZXIiIHx8IGFwcD0iRm9ydGlPUyIgfHwgYXBwPSJGT1JUSU5FVC1Gb3J0aUFuYWx5emVyIg%3D%3D

1.3 Timeline```

[2026년 1월 초]

  • 야생에서 취약점 악용 최초 확인 [출처: Arctic Wolf Threat Intelligence]

[2026년 1월 10일경]

  • 보안 연구자들이 취약점 분석 시작 [출처: GitHub Security Advisories]

[2026년 1월 15일경]

  • Fortinet, 공식 보안 권고 발표 (FG-IR-26-060) [출처: Fortinet PSIRT]

[2026년 1월 중순]

  • 패치 버전 릴리스 [출처: Fortinet PSIRT]

[2026년 1월 말]

  • 대규모 공격 캠페인 확인 [출처: SOC Prime, Arctic Wolf]
---

## 🔍 Detailed Vulnerability Mechanism Analysis

### 2.1 FortiCloud SSO Architecture

**[Source: SecPod Blog - "From SSO to SOS"]**  
https://www.secpod.com/blog/from-sso-to-sos-how-cve-2026-24858-gave-hackers-the-keys-to-your-fortinet-gear/

FortiCloud SSO is a SAML 2.0-based Single Sign-On mechanism that operates with the following structure:```
[정상 인증 흐름]

1. 사용자 → FortiGate 관리 인터페이스 접근
2. FortiGate → FortiCloud SSO로 리다이렉트
3. FortiCloud → SAML 인증 요청 생성
4. 사용자 → FortiCloud에 자격증명 입력
5. FortiCloud → SAML 응답 생성 및 서명
6. FortiCloud → SAML 응답을 FortiGate로 전송
7. FortiGate → SAML 응답 검증
8. FortiGate → 세션 생성 및 접근 허용

2.2 Vulnerability Occurrence Mechanism

[Source: SecPod Blog, Arctic Wolf Analysis]

The core issue of CVE-2026-24858 is a flaw in the SAML response validation process:``` [취약점 악용 흐름]

  1. 공격자 → 조작된 SAML 응답 생성

    • 서명 검증을 우회하는 특수 구조 사용
    • 또는 서명 검증 단계 자체를 건너뛰는 경로 활용
  2. 공격자 → FortiGate로 직접 SAML 응답 전송

    • FortiCloud를 거치지 않고 직접 전송
    • 또는 중간자 공격으로 정상 응답 변조
  3. FortiGate → 검증 실패

    • SAML 서명 검증 로직 우회
    • 발행자(Issuer) 검증 미흡
    • 타임스탬프 검증 부재
  4. FortiGate → 관리자 세션 생성

    • 공격자가 지정한 사용자 ID로 세션 생성
    • 일반적으로 "admin" 권한으로 생성됨
  5. 공격자 → 완전한 관리자 권한 획득

### 2.3 Technical Vulnerability Details

**[Source: SecPod Technical Analysis]**

The vulnerability occurs in the following 3 main areas:

#### A. Insufficient SAML Response Signature Verification```xml


  
    
      
    
    VALID_SIGNATURE
  
  
    
      [email protected]
    
  




B. Issuer Verification Flaw

FortiGate does not properly verify that the issuer of the SAML response is actually FortiCloud:```python

취약한 검증 로직 (의사코드)

def verify_saml_response(response): issuer = response.get_issuer() # 문제: issuer 검증이 충분하지 않음 if issuer: # 단순히 issuer가 존재하는지만 확인 return True return False

공격자는 임의의 issuer 값을 설정 가능

#### C. Timing and Reuse Attack Vulnerabilities

Missing or insufficient timestamp and anti-reuse mechanisms in SAML responses:```
- NotBefore / NotOnOrAfter 속성 검증 부재
- SAML Assertion ID의 재사용 방지 미흡
- 동일한 SAML 응답을 여러 번 사용 가능

2.4 Attack Complexity Analysis

[Source: Arctic Wolf Blog]
https://arcticwolf.com/resources/blog/cve-2026-24858/

ElementAssessmentDescription
Technical DifficultyLowEasily exploitable using publicly available SAML libraries
Required Prior KnowledgeMediumBasic understanding of the SAML protocol required
Required Access PrivilegesNoneDirectly accessible from the internet
Detection LikelihoodLowDifficult to distinguish from normal SSO logins
ReproducibilityHighBehaves consistently across all vulnerable versions

🎯 Affected Products and Versions

3.1 Affected Products and Patch Versions

[Source: Fortinet PSIRT Advisory FG-IR-26-060]
https://www.fortiguard.com/psirt/FG-IR-26-060

FortiOS

Vulnerable VersionsPatch VersionsStatus
7.0.0 - 7.0.167.0.17 and laterPatchable ✅
7.2.0 - 7.2.107.2.11 and laterPatchable ✅
7.4.0 - 7.4.67.4.7 and laterPatchable ✅
7.6.0 - 7.6.27.6.3 and laterPatchable ✅

Version check command:```bash get system status

출력에서 "Version" 필드 확인

#### FortiProxy

| Vulnerable Version | Patched Version | Status |
|------------|----------|------|
| 7.0.0 - 7.0.19 | 7.0.20 and later | Patchable ✅ |
| 7.2.0 - 7.2.12 | 7.2.13 and later | Patchable ✅ |
| 7.4.0 - 7.4.6 | 7.4.7 and later | Patchable ✅ |
| 7.6.0 - 7.6.1 | 7.6.2 and later | Patchable ✅ |

#### FortiPAM

| Vulnerable Version | Patched Version | Status |
|------------|----------|------|
| 1.0.0 - 1.0.3 | 1.0.4 and later | Patchable ✅ |
| 1.1.0 - 1.1.2 | 1.1.3 and later | Patchable ✅ |
| 1.2.0 - 1.2.1 | 1.2.2 and later | Patchable ✅ |
| 1.3.0 | 1.3.1 and later | Patchable ✅ |

#### FortiSwitchManager

| Vulnerable Version | Patched Version | Status |
|------------|----------|------|
| 7.0.0 - 7.0.5 | 7.0.6 and later | Patchable ✅ |
| 7.2.0 - 7.2.6 | 7.2.7 and later | Patchable ✅ |
| 7.4.0 - 7.4.1 | 7.4.2 and later | Patchable ✅ |

### 3.2 Vulnerability Impact Conditions

**[Source: Fortinet PSIRT]**

This vulnerability affects systems when **all** of the following conditions are met:

1. ✅ FortiCloud SSO is **enabled**
2. ✅ The management interface is **exposed to the internet**
3. ✅ A vulnerable firmware version is in use

**Checking FortiCloud SSO activation:**```bash
config system saml-service-provider
    show
end

# "forticloud-sso" 항목의 status 확인
# status가 "enable"이면 취약

3.3 Global Exposure Status

[Source: FOFA Search Engine, January 2026 search results]``` FOFA 검색 쿼리: app="FORTINET-FortiManager" || app="FortiOS" || app="FORTINET-FortiAnalyzer"

검색 결과: 1,100,000+ 노출된 시스템

**Regional Distribution (Top 5 Countries):**
Download Tool