CVE-2025-59719
critical · 9.8An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
9.8
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2025-12-09
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-347
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortiweb | >= 7.4.0, <= 7.4.9 |
| fortinet | fortiweb | >= 7.6.0, <= 7.6.4 |
| fortinet | fortiweb | 8.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-59719