Fortinet disclosed CWE-602 authorization bypass flaws in FortiManager and FortiAnalyzer that let authenticated low-privilege users reach privileged web-console functions and perform unauthorized operations by sending crafted requests. The advisories say affected releases span multiple FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData branches, while newer branches such as FortiAnalyzer 7.6 and FortiManager 7.6 are not affected and fixed versions are available for supported lines. Fortinet credited researchers from Orange Cyberdéfense, Orange CERT-CC, and Synacktiv for responsible disclosure.
Synacktiv detailed how the FortiManager issue, tracked as CVE-2024-23666, allowed a user with read-only or restricted privileges to access administrative features including full configuration backup, configuration import upload, and the remote SSH web console for managed FortiGate devices. Exported backups could expose hashed or encrypted credentials for FortiManager and managed devices, enabling further privilege escalation, and the configuration import path could be chained with CVE-2023-42791 to obtain root access on the underlying system. The researchers also published detection guidance aimed at spotting suspicious configuration downloads by non-admin accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Fortinet published advisory FG-IR-23-396 for another client-side enforcement of server-side security vulnerability affecting multiple FortiAnalyzer and FortiManager product lines. The company said an authenticated attacker with at least read-only permissions could execute sensitive operations by sending crafted requests, and credited Synacktiv researchers for the disclosure.
Fortinet published advisory FG-IR-23-187 for a client-side enforcement of server-side security flaw affecting FortiManager and FortiAnalyzer products. The advisory said a remote attacker with low privileges could access a privileged web console and execute some unauthorized commands, and it credited Orange Cyberdéfense and Orange CERT-CC for responsible disclosure.
Synacktiv published technical details about multiple FortiManager vulnerabilities, including an authorization bypass later identified as CVE-2024-23666 that lets a low-privilege authenticated user access administrative features. The write-up described impacts including configuration export, configuration import upload abuse, and access to the remote SSH web console for managed FortiGate devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.