Fortinet FortiManager Authentication Bypass Allows FortiGate Impersonation
A critical vulnerability in FortiManager and FortiManager Cloud could allow remote attackers to impersonate managed FortiGates if a specific CLI option is configured.

Fortinet has issued a security advisory detailing a critical authentication bypass vulnerability affecting its FortiManager and FortiManager Cloud products. The flaw, identified as CVE-2026-36595, carries a CVSSv3 score of 7.3 and could enable a remote, unauthenticated attacker to impersonate any FortiGate managed by an affected FortiManager instance.
The vulnerability hinges on a specific configuration within the Command Line Interface (CLI) of the FortiManager. If the fgfm-peercert-withoutsn option is enabled, an attacker possessing a valid digital certificate can craft specific FortiManager (FGFM) requests to achieve the impersonation. This bypasses normal authentication mechanisms, allowing the attacker to gain control over the security posture of the targeted FortiGate devices.
FortiManager versions 7.2, 7.4, and 7.6, along with their corresponding Cloud versions, are affected by this vulnerability. Specifically, FortiManager 7.2.5 through 7.2.9, 7.4.3 through 7.4.5, and 7.6.1 are vulnerable. Similarly, FortiManager Cloud versions 7.2.5 through 7.2.9, 7.4.3 through 7.4.5, and 7.6.1 are also impacted. FortiManager version 8.0 is noted as not affected.
Fortinet recommends upgrading to specific patched versions to remediate the vulnerability. For affected FortiManager 7.6 instances, users should upgrade to 7.6.2 or later. For FortiManager 7.4, upgrades to 7.4.6 or later are required. Similarly, FortiManager 7.2 users must upgrade to 7.2.10 or later. The same upgrade paths apply to the corresponding FortiManager Cloud versions.
As a temporary workaround, Fortinet suggests disabling the fgfm-peercert-withoutsn CLI option. This can be achieved by executing the commands config system global, followed by set fgfm-peercert-withoutsn disable, and then end. This mitigation should be applied until systems can be upgraded to the patched versions.
This vulnerability highlights the critical importance of secure configuration management, particularly for centralized network management platforms like FortiManager. The ability for an attacker to impersonate managed devices can lead to widespread compromise, including policy manipulation, traffic redirection, and further network intrusion. Organizations relying on FortiManager should prioritize applying the available patches or implementing the suggested workaround to mitigate the risk.