VDB
GCVE-110-NCSC-2026-61
GCVE-110-NCSC-2026-61
Advisory PublishedCVSS 8.1/10
A vulnerability in Fortinet FortiOS versions 7.6.0 to 7.6.4 allows unauthenticated attackers to bypass LDAP authentication for Agentless VPN or FSSO policy under specific LDAP server configurations.
Weaknesses (CWE)
CWE-305Authentication Bypass by Primary WeaknessCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-134Use of Externally-Controlled Format StringCWE-940Improper Verification of Source of a Communication Channel
Risk Scores
CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Fortinet | vers:unknown/* | — | — |
Browse GCVE Records
77,751 records in the GCVE database · Updated August 8, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.