logo

FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication

ID: 378892b5-412b-5fc8-9db4-ab008db9c239

STIX ID: report--378892b5-412b-5fc8-9db4-ab008db9c239

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet disclosed CVE-2026-22153, a high-severity authentication bypass in FortiOS (affecting 7.6.0–7.6.4) where improper handling in the fnbamd daemon allows LDAP authentication to be bypassed when LDAP servers permit unauthenticated (anonymous) binds; administrators are advised to upgrade to FortiOS 7.6.5 or later and disable unauthenticated binds as a workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.