← All CVEs

CVE-2025-59719

critical · 9.8

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

9.8
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2025-12-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-347

Affected products

VendorProductAffected versions
fortinetfortiweb>= 7.4.0, <= 7.4.9
fortinetfortiweb>= 7.6.0, <= 7.6.4
fortinetfortiweb8.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-59719