# FortiWeb auth bypass and path traversal, admin creation

Source: https://startwithidentity.com/cves/cve-2025-64446/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

FortiWeb had an authentication bypass combined with path traversal that let an unauthenticated attacker create an administrative user. CVSS 9.8. CISA added it to KEV around 14 November 2025.

## Why it matters

This is not a SAML bug. It is a management-plane auth bypass on the same product family that later failed FortiCloud SSO. Two independent ways to become admin on a WAF, both exploited, both on KEV, is a pattern: the identity of the appliance is the target, not a single protocol.

## What to do

- Patch FortiWeb for CVE-2025-64446 and then take the SSO fixes ([CVE-2025-59719](https://startwithidentity.com/cves/cve-2025-59719/), [CVE-2026-24858](https://startwithidentity.com/cves/cve-2026-24858/)).
- Hunt for admin accounts that were not created by your change process, especially from mid-November 2025.
- Take FortiWeb management off the internet. Put it behind a jump path with [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/).

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2025-64446](https://nvd.nist.gov/vuln/detail/CVE-2025-64446)
- CISA KEV (added ~14 November 2025)
