BlackTree Security · Infrastructure · Automation · AI

One FortiCloud Account Could Reach Someone Else’s Fortinet Device

Fortinet CVE-2026-24858 allowed a FortiCloud customer to authenticate to devices registered under somebody else’s account. Attackers exploited the flaw to download configurations and create local administrator accounts for persistence.

The critical authentication bypass sits in the alternate FortiCloud SSO login path. It affects multiple Fortinet product families, including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiSwitchManager and FortiWeb.

The failure was not a stolen password or a weak customer configuration. It was a tenant-isolation problem. A valid FortiCloud identity and a registered device could become the starting point for access to a different customer’s appliance when the vulnerable cloud SSO path was enabled.

What Fortinet confirmed

QuestionAnswer
What is the flaw?CVE-2026-24858, an unauthenticated alternate-path authentication bypass in FortiCloud SSO
Is exploitation confirmed?Yes. Fortinet says the issue is known to have been exploited and locked two malicious FortiCloud accounts on 22 January 2026.
What did attackers do?Download device configurations and add local administrator accounts for persistence.
Was cloud SSO enabled by default?Not in the factory configuration, but the registration flow could enable it unless administrators disabled the relevant toggle.
Are custom identity providers affected?No. Fortinet says custom IdP configurations are not affected by this issue.
What cloud products are not affected?FortiManager Cloud, FortiAnalyzer Cloud and FortiGate Cloud are listed as not impacted.

A valid account crossed the wrong boundary

Authentication systems answer two questions: who is the user, and what tenant or device may that user reach? The Fortinet flaw broke the second question. An attacker could begin with a legitimate FortiCloud account and still land inside an appliance belonging to another account.

Fortinet disabled FortiCloud SSO on 26 January while investigating. It re-enabled the service on 27 January with vulnerable versions blocked. That server-side action reduced immediate reach, but it did not remove the need to patch appliances or investigate configuration access that may already have occurred.

The reported attacker actions make the incident-response path clear. A downloaded configuration can expose network topology, policies, VPN settings, identifiers and encrypted or recoverable secrets. A newly created local administrator can outlive the cloud SSO route that enabled the original intrusion.

What defenders should do

  • Install the fixed release for every affected Fortinet product. Use the version matrix in FG-IR-26-060 and verify that no vulnerable branch remains reachable.
  • Review cloud SSO status. Confirm whether FortiCloud SSO was enabled, when it was enabled and which administrator accounts used it.
  • Audit local administrators. Investigate recently created or modified accounts, especially the names and indicators listed by Fortinet.
  • Assume configuration downloads matter. If logs suggest a configuration was accessed, rotate exposed credentials and review dependent systems after preserving evidence.
  • Search for cross-account anomalies. Review source addresses, FortiCloud identities, login times and administrative actions that do not match normal ownership.
  • Restrict management interfaces. Keep appliance administration off the public internet and limit access to controlled management networks.

The BlackTree view

This incident is more consequential than a conventional login bypass because it undermined the isolation expected from a shared cloud identity service. The attacker did not need to steal the target customer’s credentials. The platform accepted the wrong tenant relationship.

Fortinet’s service-side block was an important emergency control. Defenders still need to answer whether an intruder downloaded the blueprint of their network or created an administrator account that remains active after the cloud route closed.

Sources and publication details

Leave a Reply

Your email address will not be published. Required fields are marked *