CVE-2026-22153HIGH 8.1EPSS p48.2%

CVE-2026-22153CVE-2026-22153

Description

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.70% probability of exploitation · percentile 48.2% · 2026-06-19T12:03:05Z
Published2026-02-10
Last modified2026-02-12

Underlying weaknesses· 1

CWE-305

References

  1. https://fortiguard.fortinet.com/psirt/FG-IR-25-1052

1

TypeTargetConfidenceTier
WeaknessAuthentication Bypass by Primary Weaknesscwe-3050%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
CVE
CVE-2022-40684
CVE
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
CVE
CVE-2025-22862
CVE
Fortinet FortiOS Default Configuration Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.