← Back to browse · API

CVE-2025-59719

Severity
CRITICAL
CVSS
9.1
EPSS
0.25048
Risk score
45.17
CISA KEV
No
PoC
No
Published
2025-12-09
Modified
2026-07-14
First seen
2026-08-07
Aliases
EUVD-2025-202191, GHSA-CHQ4-235Q-JP7W
Products
Fortinet:FortiWeb 7.4.0 ≤7.4.9, Fortinet:FortiWeb 7.6.0 ≤7.6.4, Fortinet:FortiWeb 8.0.0
Sources
euvd EUVD-2025-202191

Description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

References