Security Vulnerability Allows Authentication Bypass in FortiCloud SSO
Picus Security has identified a critical vulnerability, CVE-2025-59718, in FortiCloud's Single Sign-On feature, potentially allowing unauthorized administrative access.
Cybersecurity firm Picus Security has disclosed a critical vulnerability, identified as CVE-2025-59718, impacting the FortiCloud Single Sign-On (SSO) feature. This flaw permits unauthenticated remote attackers to gain administrative privileges.
The vulnerability is categorized under Improper Verification of Cryptographic Signature (CWE-347). Attackers can exploit this by sending a specially crafted Security Assertion Markup Language (SAML) packet to the /remote/saml/login endpoint. This action tricks the system into accepting a forged authentication request, granting the attacker administrative rights.
This issue affects multiple Fortinet products, including FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb. While FortiCloud SSO is not enabled by default, it activates automatically when a device is registered to FortiCare, unless explicitly disabled by the user. Picus Security has released details of the vulnerability to aid organizations in testing and enhancing their security posture. The company provides simulation tools to test defenses against such attacks. Remediation involves checking for Fortinet security updates and verifying secure configuration settings.