> JWT used for authentication in web GUI signed with static key
[DATE: 08/09/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
9.6
An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT
Revised on 2026-09-08 00:00:00