FORTINET Security Advisory

Published Date: Not specified

Advisory Summary

⬛ ⚠️ Title: JWT authentication bypass risk in FortiMonitorOnSight (FortiMonitorOnSight web GUI)
πŸ“Œ Summary (what’s happening):
FortiMonitorOnSight contains a vulnerability related to Sensitive Information in Source Code (CWE-540) where a JWT used for authentication in the web GUI is signed with a static key. This can enable a remote, unauthenticated attacker to forge or reuse JWTs to bypass authentication, potentially reaching protected functionality without valid credentials.

🚨 Recommended actions (do now):
1. Check FortiMonitorOnSight exposure: restrict management/portal access via IP allowlists, VPN, or zero-trust access.
2. Apply the PSIRT fix referenced by Fortinet (per affected versions).
3. Rotate/replace any credentials and tokens if the static JWT signing key (or related logic) was leveraged.
4. Review web access logs for suspicious JWT activity and unusual unauthenticated hits to auth-protected endpoints.
5. Harden admin planes: enforce MFA where supported for any remaining auth flows, and segment monitoring interfaces from general networks.

πŸ”—

Reference: Vendor Advisory