Fortinet SSO Admin Login Flaw: New SAML Bypass CVEs Spur Multi-Product Patch Planning

Abstract digital illustration depicting a futuristic network or cloud computing environment, with glowing teal and orange icons or nodes representing different applications or services connected by lines or data streams, showcasing the concept of interconnected systems and digital transformation.

Enterprises that rely on SAML single sign-on for Fortinet administrator access are being urged to review patch levels after two newly listed vulnerabilities were described as authentication bypass issues tied to SAML data handling. The issues are tracked as CVE-2025-59718 and CVE-2025-59719 in the NIST National Vulnerability Database, with at least one entry carrying a CVSS 9.8 rating.

Based on vendor advisory details echoed in downstream bulletins, exposure is linked to a common configuration: environments where "Allow administrative login using FortiCloud SSO" is enabled and SAML is used to control administrator sign-in. In that setup, crafted SAML data could allow an attacker to bypass intended checks and obtain privileged access, shifting risk from an application-layer defect to control-plane impact.

For operations teams, remediation is not necessarily isolated to a single appliance. Affected scope spans FortiOS and, in certain version ranges, additional Fortinet products including FortiProxy, FortiSwitchManager, and FortiWeb. That breadth can turn a security bulletin into a coordinated patch window, especially where the same identity stack is used across perimeter, management, and application-delivery infrastructure.

While patching is positioned as the primary fix, interim risk reduction measures cited by advisories include limiting administrative interfaces to trusted networks and, where feasible, temporarily disabling FortiCloud SSO-based administrative login until updates are deployed.

After updates are applied, security teams may also want to treat identity-plane activity as high-impact: validate administrator account integrity, review authentication logs for unusual SAML-related behavior around the disclosure period, and confirm that device configurations and policies have not been altered.

Sources: NIST NVD, NIST NVD, CSA Singapore, Secure ISS

By the ID Tech Editorial Team