CVE-2025-48840
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unaut
Exploited
Not listed
EPSS
0.005
37.6th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet
Description
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.
Weakness: CWE-290
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb Check your version | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiWeb
Credit
External
Vendor remediation
Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.9 or above