
⚠️ FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication Source: https://cybersecuritynews.com/fortios-ldap-authentication-bypass-vulnerability/ Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies. The flaw resides in the fnbamd daemon and requires specific LDAP server configurations enabling unauthenticated binds. The issue stems from improper handling of LDAP authentication requests. An attacker could exploit this under certain setups, such as those permitting anonymous binds, to gain unauthorized access without valid credentials. #cybersecuritynews #vulnerability
Post summary
Fortinet disclosed a high‑severity FortiOS authentication bypass (CVE‑2026‑22153) that lets attackers sidestep LDAP authentication under specific server configurations. No patches, exploits, or active exploitation reports are mentioned.

















