logo

FortiOS Vulnerability Enables LDAP Authentication Bypass

ID: 4ab7076f-bae0-5625-8a90-46c8f0488496

STIX ID: report--4ab7076f-bae0-5625-8a90-46c8f0488496

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Divya

...
...

**Fortinet CVE-2026-22153 (High, CVSS 7.5)** — A critical authentication bypass in the fnbamd component of FortiOS can allow unauthenticated attackers to bypass LDAP-based authentication (Agentless VPNs and FSSO) when the backend LDAP server accepts anonymous/unauthenticated binds; Fortinet recommends upgrading affected 7.6.x devices to FortiOS 7.6.5+ or disabling unauthenticated binds on the LDAP server as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.