CVE-2026-26035

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, F

Severity
High 8.8
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.007
53.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Aug 12, 2026
Assigned by fortinet

Description

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

Weakness: CWE-287

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Check your version Web & Application Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiWeb

Credit

Internally discovered as part of a Fortinet audit.

Vendor remediation

Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above Upgrade to FortiWeb version 7.4.12 or above Upgrade to upcoming FortiWeb version 7.2.13 or above Upgrade to upcoming FortiWeb version 7.0.13 or above

Something wrong here?