# FortiWeb FortiCloud SSO SAML bypass

Source: https://startwithidentity.com/cves/cve-2025-59719/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

FortiWeb accepted a crafted FortiCloud SSO [SAML](https://startwithidentity.com/glossary/saml/) message the same way FortiOS did in [CVE-2025-59718](https://startwithidentity.com/cves/cve-2025-59718/). CWE-347, CVSS 9.8, disclosed 9 December 2025. CISA's KEV addition named 59718 first. Do not read that as "FortiWeb is fine."

## Why it matters

WAF management planes are a favorite place to hide. A FortiWeb admin session can change inspection policy, plant allow-lists, and cover the next stage. Pair this with [CVE-2025-64446](https://startwithidentity.com/cves/cve-2025-64446/) (FortiWeb auth bypass / path traversal, also on KEV) and you have two independent ways onto the same box.

## What to do

- Patch FortiWeb and disable FortiCloud SSO if you do not use it.
- Audit FortiWeb admin accounts and policy diffs from mid-December 2025.
- Apply the later [CVE-2026-24858](https://startwithidentity.com/cves/cve-2026-24858/) fix. Devices patched only for 59718/59719 stayed exposed.

## After you patch

A SAML bypass means the service provider accepted an assertion it should have rejected, so anyone who exploited it authenticated as a real user and left a normal-looking log line.

- **Revoke every session** issued by the affected service provider, then rotate its session signing keys. Patching stops new forgeries and does nothing about sessions already minted.
- **Audit administrative accounts and group memberships** for changes during the exposure window. Signing in as an administrator is the point of this class, and adding a second account is the standard persistence step.
- **Rotate the identity provider signing certificate** if the flaw involved signature validation, and confirm the service provider pins the expected certificate rather than trusting anything in the assertion.
- **Check your own implementation for the same class**: exact-match comparison on verification results, rejection of unexpected signature algorithms, and audience and recency checks on every assertion. See [SAML 2.0](https://startwithidentity.com/standards/saml-2-0/) and [SAML vs OIDC](https://startwithidentity.com/guides/fundamentals/saml-vs-oidc/).

## Sources

- [NVD: CVE-2025-59719](https://nvd.nist.gov/vuln/detail/CVE-2025-59719)
- Fortinet PSIRT advisories for FortiCloud SSO
