CVE-2026-26035

Published Aug 12, 2026

Last updated 8 days ago

Overview

Description
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortiweb

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@fortinet.com
CWE-287

Social media

Hype score
Not currently trending
  1. You can log into a FortiWeb console with a random username and password. One setting makes it possible. CVE-2026-26035: admin accounts using remote RADIUS-type authentication with the wildcard option enabled will accept random credentials. Unauthenticated. GUI and CLI. Fixed in

    @uwillc

    20 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/40UzccobEM

    @aMI_KUH95291

    16 Aug 2026

    122 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468)https://t.co/v2LGpBaCpz "FortiWebやFortiManagerはネットワーク境界やセキュリティ機器の管理に

    @catnap707

    16 Aug 2026

    247 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  4. Fortinet、FortiWebとFortiManagerの認証関連 脆弱性を修正-未認証ログイン・FortiGateなりすましの恐れ(CVE-2026-26035/CVE-2026-70468) https://t.co/zzkbT14v53 #セキュリティ対策Lab #security #securitynews #脆弱性

    @securityLab_jp

    16 Aug 2026

    158 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Fortinet has patched multiple critical authentication flaws across FortiWeb, FortiManager & FortiClient. 1. CVE-2026-26035 (FortiWeb): Improper RADIUS wildcard auth lets attackers log in with random creds. 2. CVE-2026-70468 (FortiManager): Auth bypass in FGFM protocol

    @techepages

    13 Aug 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit availa

    @AretiqAI

    12 Aug 2026

    431 Impressions

    0 Retweets

    7 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.