CVE-2026-23708
Last modified
CVE-2026-23708 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortisoar | >= 7.5.0, < 7.5.3 |
| Fortinet | Fortisoar | >= 7.6.0, < 7.6.4 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-26-101Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23708?
How severe is CVE-2026-23708?
How do I fix CVE-2026-23708?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23698Vtiger CRM through 8.4.0 contains an authenticated remote co…8.6
- CVE-2026-23699AP180 series with firmware versions prior to AP_RGOS 11.9(4)…8.6
- CVE-2026-2370GitLab has remediated an issue in GitLab CE/EE affecting all…8.8
- CVE-2026-23702An OS command injection vulnerability exists in XWEB Pro ve…8.8
- CVE-2026-23703The installer of FinalCode Client provided by Digital Arts I…8.5
- CVE-2026-23704A non-administrative user can upload malicious files. When a…6.5
- CVE-2026-23709Rejected reason: Not used
- CVE-2026-2371The Greenshift – animation and page builder blocks plugin fo…5.3
- CVE-2026-23710Rejected reason: Not used
- CVE-2026-23711Rejected reason: Not used
- CVE-2026-23712Rejected reason: Not used
- CVE-2026-23713Rejected reason: Not used
Are you affected by CVE-2026-23708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
