Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS and FortiProxy. The vendor has rated the vulnerability at CVSSv3 7.3 (high severity). According to the advisory, it allows a remote, unauthenticated attacker to carry out a Man-in-the-Middle (MITM) attack on the communication channel between the ZTNA portal and the target backend server. Organizations using agentless ZTNA through FortiOS or FortiProxy should immediately refer to the full text of the advisory to determine affected versions and available updates.
Technical details of the vulnerability
The vulnerability belongs to the CWE-295 — Improper Certificate Validation class. The core issue is that the agentless ZTNA portal in FortiOS and FortiProxy does not sufficiently validate certificates when establishing a connection to backend servers — the web applications to which the ZTNA portal proxies user traffic.
This means that an attacker who can position themselves between the ZTNA portal and the target backend server can intercept, read, and modify transmitted data. It is important to emphasize that, according to the Fortinet advisory, no authentication is required to exploit this issue.
Affected products, according to the advisory:
- FortiOS — the operating system of FortiGate devices
- FortiProxy — Fortinet’s proxy solution
The specific ranges of affected versions and the version numbers of fixed releases are not stated in the provided text of the advisory. A CVE identifier is also not published in the publicly available portion of the advisory. The status of active exploitation is currently unknown.
Impact assessment
The agentless ZTNA portal is a component of a Zero Trust Network Access architecture that allows users to access internal web applications via a browser without installing an agent on the endpoint. The portal acts as an intermediary between the user and the backend server, and it is this segment — between the portal and the backend — that is vulnerable.
A successful MITM attack on this segment potentially allows an attacker to:
- Intercept data transmitted between the portal and protected applications, including credentials and sensitive information
- Modify backend server responses by injecting malicious content
- Compromise sessions of users working through the ZTNA portal
The highest risk is to organizations that have deployed agentless ZTNA access to critical internal applications, especially in scenarios where the network path between FortiGate/FortiProxy and the backend servers traverses untrusted network segments.
Recommendations
- Check whether your infrastructure uses agentless ZTNA mode via FortiOS or FortiProxy
- Refer to the full FG-IR-26-174 advisory on the FortiGuard PSIRT portal for information about affected versions and available updates
- Monitor updates on the Fortinet PSIRT advisory page, as the advisory may be supplemented with details on affected versions and fixes
- As a temporary measure, evaluate additional network segmentation between the ZTNA portal and backend servers to minimize the attack surface on this segment
We have previously covered critical vulnerabilities in Fortinet products — the current advisory confirms that the FortiOS and FortiProxy product lines remain subject to regular security fixes.
The CVSSv3 7.3 score indicates high severity, and the absence of an authentication requirement lowers the barrier to entry for an attacker. Organizations using agentless ZTNA should give priority to checking whether the advisory applies to their FortiOS and FortiProxy versions and plan to update as soon as the vendor releases fixed versions.