CVE-2026-40688

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacke

Severity
Medium 6.7
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.009
57.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet

Description

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Weakness: CWE-787

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Check your version Web & Application Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiWeb

Credit

Fortinet is pleased to thank Jason McFadyen of TrendAI Research for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiWeb version 8.0.4 or above Upgrade to FortiWeb version 7.6.7 or above Upgrade to FortiWeb version 7.4.12 or above

Something wrong here?