---
id: CVE-2023-50176
title: >-
  A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3,
  FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to
  execute unauthorized code or commands via phishing SAML authentication link.
summary: >-
  A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3,
  FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to
  execute unauthorized code or commands via phishing SAML authentication link.
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-384
vendor: fortinet
product: fortios
affected:
  - 'fortios >= 7.0.0, < 7.0.14'
  - 'fortios >= 7.2.0, < 7.2.8'
  - 'fortios >= 7.4.0, < 7.4.4'
patched:
  - fortios 7.4.4
published: '2024-11-12'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-50176'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-475'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00402
epssPercentile: 0.34216
ingestedAt: '2026-08-24T14:04:34.086Z'
---

## Overview

A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

## Affected

- `fortios >= 7.0.0, < 7.0.14`
- `fortios >= 7.2.0, < 7.2.8`
- `fortios >= 7.4.0, < 7.4.4`

## Remediation

Upgrade past the affected range:

- `fortios 7.4.4`
