High severity7.1NVD Advisory· Published Jul 12, 2021· Updated Jun 17, 2026
CVE-2021-26088
CVE-2021-26088
Description
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.
Affected products
3- cpe:2.3:a:fortinet:fortinet_single_sign-on:*:*:*:*:*:*:*:*Range: <6.4.6
- Range: <=5.0.295
- Fortinet/Fortinet FSSO Windows DC Agent, FSSO Windows CAv5Range: FSSO Windows DC Agent 5.0.295, 5.0.294; FSSO Windows CA 5.0.295, 5.0.294
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-191nvdVendor Advisory
News mentions
0No linked articles in our index yet.