NewsFortinet PSIRT2026-09-08 07:00 UTC

JWT used for authentication in web GUI signed with static key

Teaser from the source

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

This is the RSS-feed teaser. Read the full article at the original source.

Read at Fortinet PSIRT →

Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-170

ID