FortiWeb Authentication Bypass Vulnerability Allows Unauthorized Access

⚠️ FortiWeb Authentication Bypass Vulnerability Let Attackers Log in As Any Existing User | Read more: https://lnkd.in/d3Zy4JW2 ✅ CVE-2025-52970 lets attackers bypass authentication to log in as any user on FortiWeb systems. ✅ FortiWeb 7.0-7.6 versions are vulnerable. ✅ Attackers manipulate cookie parameters to force zero-filled encryption keys. #cybersecuritynews #vulnerability

  • text

Impersonate any user? Sounds like attackers just got VIP access.

FortiWeb just became FortiOpen.

Rui Seabra

Free Software Consultant; Systems & Automation Engineering at SIBS, SA; ANSOL, GA Board Member; Actor

2mo

No surprise to me, they don't even think it's worth it to log API auth failures...

Like
Reply
Pablo García Álvarez

System Administration 💻 | Cybersecurity 🛡 | Pentesting 🕷 - Preparing PT1 in TryHackMe 🦠 | Linux, Windows

2mo

🙃 I feel safe 🥲

Like
Reply
Odd-Arne Haraldsen

IT Operations Manager på Svenljunga Kommun

2mo

Kinda sounds like it should be higher than 7.7 on the scale.

Like
Reply
Albert Estevez Polo

Field CTO Global driving cybersecurity innovation and customer engagement

2mo

wow…

Like
Reply

Thanks for highlighting this, always critical to stay ahead of such vulnerabilities. Organizations should prioritize patching and review their cookie security measures to avoid potential breaches. Stay safe out there!

Like
Reply
See more comments

To view or add a comment, sign in

Explore content categories