NewsFortinet PSIRT2026-09-08 07:00 UTC
JWT used for authentication in web GUI signed with static key
Teaser from the source
CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00
This is the RSS-feed teaser. Read the full article at the original source.
Read at Fortinet PSIRT →More on authentication
Other advisories
- CVE-2026-62367nonego code.vikunja.io/api: Authentication Bypass by Spoofing
- ghsa:GHSA-4hv6-xc92-j86gmediumVikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes
- osv:GHSA-4hv6-xc92-j86gnoneVikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes
- CVE-2026-62367nonego code.vikunja.io/api: Authentication Bypass by Spoofing
- CVE-2026-107808noneNginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
- CVE-2026-107808highNginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
- osv:GHSA-r44w-v6gf-x3p6nonepyLoad has an authentication bypass in API key validation (check_apikey cache)
- ghsa:GHSA-r44w-v6gf-x3p6highpyLoad has an authentication bypass in API key validation (check_apikey cache)
Other news entries
- Newsthehackernews2026-10-09Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
- Newssecurityweek2026-10-09Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- Newssecurityweek2026-10-08SonicWall and Splunk Patch Critical Vulnerabilities
- Newscsoonline2026-10-08SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
- Newsthehackernews2026-10-07SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
- Newsbleepingcomputer2026-10-07Hackers exploit critical Atlassian flaw after public PoC release
- Newsbleepingcomputer2026-10-06Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
- Newssecurityweek2026-10-03Fortra Patches Critical Vulnerabilities in BoKS
Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-170
ID