Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN756
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running FortiOS versions prior to 7.6.5.
 
=====================================================================

https://www.fortiguard.com/psirt/FG-IR-25-1052
_____________________________________________________________________


LDAP authentication bypass in Agentless VPN and FSSO

Summary

An Authentication Bypass by Primary Weakness vulnerability [CWE-305]
in FortiOS fnbamd may allow an unauthenticated attacker to bypass
LDAP authentication of Agentless VPN or FSSO policy, under specific
LDAP server configuration.


Version 	Affected 	Solution

FortiOS 8.0 	Not affected 	Not Applicable
FortiOS 7.6 	7.6.0 through 7.6.4 	Upgrade to 7.6.5 or above
FortiOS 7.4 	Not affected 	Not Applicable
FortiOS 7.2 	Not affected 	Not Applicable
FortiOS 6.4 	Not affected 	Not Applicable
Follow the recommended upgrade path using our tool at:
https://docs.fortinet.com/upgrade-tool


Workaround:

Disable unauthenticated bind on the LDAP server.

For example, LDAP unauthenticated binds can be disabled in Windows
Active Directory (starting from Windows Server 2019) via the
following PowerShell code snippet:

$configDN = (Get-ADRootDSE).configurationNamingContext
$dirSvcDN = "CN=Directory Service,CN=Windows NT,CN=Services,$configDN"
Set-ADObject -Identity $dirSvcDN -Add @{'msDS-Other-Settings'='DenyUnauthenticatedBind=1'}

Virtual Patch named "FG-VD-10009566.0day." is available in
FMWP db update 26.063


Acknowledgement
Fortinet is pleased to thank Jort Geurts from the Actemium Cyber
Security Team for reporting this vulnerability under responsible
disclosure.


Timeline

2026-02-10: Initial publication
2026-07-04: Added IPS package info

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




