- Description
- An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortiweb
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@fortinet.com
- CWE-287
- Hype score
- Not currently trending
You can log into a FortiWeb console with a random username and password. One setting makes it possible. CVE-2026-26035: admin accounts using remote RADIUS-type authentication with the wildcard option enabled will accept random credentials. Unauthenticated. GUI and CLI. Fixed in
@uwillc
20 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/40UzccobEM
@aMI_KUH95291
16 Aug 2026
122 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468)https://t.co/v2LGpBaCpz "FortiWebやFortiManagerはネットワーク境界やセキュリティ機器の管理に
@catnap707
16 Aug 2026
247 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/zzkbT14v53 #セキュリティ対策Lab #security #securitynews #脆弱性
@securityLab_jp
16 Aug 2026
158 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Fortinet has patched multiple critical authentication flaws across FortiWeb, FortiManager & FortiClient. 1. CVE-2026-26035 (FortiWeb): Improper RADIUS wildcard auth lets attackers log in with random creds. 2. CVE-2026-70468 (FortiManager): Auth bypass in FGFM protocol
@techepages
13 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit availa
@AretiqAI
12 Aug 2026
431 Impressions
0 Retweets
7 Likes
5 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6B9458FC-3403-4125-A4A9-C15E1A4AFD29",
"versionEndExcluding": "7.2.13",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
"matchCriteriaId": "00447564-4A90-4194-85FF-A8C047796A5F",
"versionEndExcluding": "7.4.12",
"versionStartIncluding": "7.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15C9CDE3-FE6F-4946-A3DC-FDD7A5F99D65",
"versionEndExcluding": "7.6.7",
"versionStartIncluding": "7.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C82F9CC0-7683-4CDE-8370-153400605B55",
"versionEndExcluding": "8.0.3",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]