Identity CVE · SAML
CVE-2025-59719FortiWeb FortiCloud SSO SAML bypass
critical · CVSS 9.8
Product: Fortinet FortiWebVendor: FortinetCWE-347Disclosed: 2025-12-09Status: PatchedProtocol deep diveNVD ↗
What broke
FortiWeb accepted a crafted FortiCloud SSO SAML message the same way FortiOS did in CVE-2025-59718. CWE-347, CVSS 9.8, disclosed 9 December 2025. CISA's KEV addition named 59718 first. Do not read that as "FortiWeb is fine."
Why it matters
WAF management planes are a favorite place to hide. A FortiWeb admin session can change inspection policy, plant allow-lists, and cover the next stage. Pair this with CVE-2025-64446 (FortiWeb auth bypass / path traversal, also on KEV) and you have two independent ways onto the same box.
What to do
- Patch FortiWeb and disable FortiCloud SSO if you do not use it.
- Audit FortiWeb admin accounts and policy diffs from mid-December 2025.
- Apply the later CVE-2026-24858 fix. Devices patched only for 59718/59719 stayed exposed.
Sources
- NVD: CVE-2025-59719
- Fortinet PSIRT advisories for FortiCloud SSO
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.