> FGFM Authentication Weakening via CLI Configuration
[DATE: 12/08/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
7.3
An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate.
Revised on 2026-08-12 00:00:00