{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-59719","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2025-09-19T04:30:39.464Z","datePublished":"2025-12-09T17:20:11.763Z","dateUpdated":"2026-03-20T12:39:05.692Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiWeb","cpes":["cpe:2.3:a:fortinet:fortiweb:8.0.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.6.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.6.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.6.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.6.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.9:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.8:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiweb:7.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"8.0.0","status":"affected"},{"versionType":"semver","version":"7.6.0","lessThanOrEqual":"7.6.4","status":"affected"},{"versionType":"semver","version":"7.4.0","lessThanOrEqual":"7.4.9","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2026-03-20T12:39:05.692Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-347","description":"Improper access control","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"}}],"solutions":[{"lang":"en","value":"Upgrade to FortiSwitchManager version 7.2.7 or above\nUpgrade to FortiSwitchManager version 7.0.6 or above\nUpgrade to FortiProxy version 7.6.4 or above\nUpgrade to FortiProxy version 7.4.11 or above\nUpgrade to FortiProxy version 7.2.15 or above\nUpgrade to FortiProxy version 7.0.22 or above\nUpgrade to FortiOS version 7.6.4 or above\nUpgrade to FortiOS version 7.4.9 or above\nUpgrade to FortiOS version 7.2.12 or above\nUpgrade to FortiOS version 7.0.18 or above\nUpgrade to FortiWeb version 8.0.1 or above\nUpgrade to FortiWeb version 7.6.5 or above\nUpgrade to FortiWeb version 7.4.10 or above\nFortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action.\nUpgrade to FortiPAM version 1.8.0 or above"}],"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-25-647","url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-647"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-59719","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-12-10T04:57:28.019701Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T16:56:59.225Z"}}]}}