Fortinet Fixes Auth Paths That Break Trust Boundaries

Fortinet patched multiple high-severity flaws on August 13 across FortiWeb, FortiManager Cloud, and FortiClient for Windows, with CSIRT Italia publishing affected-version guidance for the three high-severity CVEs. The set includes an authentication bypass in FortiWeb, an authentication bypass in FortiManager, and a memory-corruption flaw in FortiClient for Windows. In FortiWeb, the dangerous case is a non-default wildcard admin setting: when it is enabled, the appliance can match an unexpected remote username to an admin group instead of rejecting it, so a login path meant for a narrow setup becomes much wider than it looks. In FortiManager, the bypass can let an attacker impersonate a managed FortiGate device, which turns the issue into a trust problem on the management plane rather than a simple sign-in bug. For operators, the meaningful exposure depends on whether those trust mappings are in use. If FortiWeb sits in front of sensitive admin access, or FortiManager is allowed to authenticate devices through those paths, the risk is in the identity relationship the appliance accepts, not just the box itself.

Sources