---
cve: "CVE-2026-22572"
severity: "MEDIUM"
cvss: 6.8
epss: "56%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2026-03-10 18:18:12"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T04:56:46+02:00"
---

# CVE-2026-22572

> 6.8 MEDIUM

## Beschreibung

An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow  an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-26-090>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-22572) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
