> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
- URL: https://darkwebinformer.com/cve-2026-24858-fortinet-multiple-products-authentication-bypass-using-an-alternate-path-or-channel-vulnerability-severity-critical-cvss-9-8-zero-day-yes-cve-published-january-27th-2026/
- Published: 2026-01-28T00:01:22.000Z
- Updated: 2026-01-28T00:01:22.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Severity: Critical  
CVSS: 9.8  
Zero Day: Yes  
CVE Published: January 27th, 2026

Advisory: <https://github.com/advisories/GHSA-2x38-48vp-w23x>

An Authentication Bypass Using an Alternate Path or Channel vulnerability \[CWE-288\] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.