AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-23708

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-14 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Fortinet. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-23708
Severity
HIGH
CVSS
7.5
EPSS
0.28%
Fortinet

Original NVD Description

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.

Related CVEs

Other vulnerabilities affecting the same vendor(s)