CVE-2026-22153
8.1Fortinet · FortiOS
An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to circumvent LDAP authentication for Agentless VPN or FSSO policy under specific configurations.
Executive summary
A critical authentication bypass flaw in Fortinet FortiOS 7.6.0 through 7.6.4 exposes organizations to unauthorized access due to improper LDAP credential validation.
Vulnerability
This vulnerability, categorized as CWE-305, allows an unauthenticated attacker to bypass LDAP authentication mechanisms for Agentless VPN or FSSO policies. The flaw is triggered when the remote LDAP server is configured in a specific, non-standard manner.
Business impact
The ability for an unauthenticated attacker to bypass authentication controls poses a severe risk to organizational security. Successful exploitation could lead to unauthorized access to internal resources, potential data exfiltration, and the compromise of VPN sessions. With a CVSS score of 8.1, this high-severity vulnerability necessitates immediate attention to prevent unauthorized administrative or user-level access to sensitive network segments.
Remediation
Immediate Action: Upgrade to FortiOS version 7.6.5 or higher, or migrate to FortiOS version 8.0.0 or above, as specified by the vendor.
Proactive Monitoring: Review FortiOS system access logs for anomalous authentication patterns or unauthorized sessions originating from unexpected external sources.
Compensating Controls: If immediate patching is not feasible, restrict access to the affected VPN or FSSO interfaces by using IP whitelisting or by temporarily disabling the affected features until the patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete authentication bypass, organizations must prioritize the application of the provided security patches. Verify your current FortiOS build version against the affected range and schedule an update to version 7.6.5 or higher at the earliest possible maintenance window to mitigate the risk of unauthorized access.