CVE Record
[ CRITICAL ] CVE-2026-26035
FortiWeb Authentication Bypass Allows Unauthenticated Login
An improper authentication flaw in FortiWeb lets remote unauthenticated attackers log in with any credentials. Affects versions 7.0.x through 8.0.x; patch available.
- Vendor
- Fortinet
- Product
- FortiWeb
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
Improper authentication (CWE-287) in Fortinet FortiWeb allows a remote unauthenticated attacker to log in to the management GUI or CLI using any arbitrary username and password combination.
Affected versions
| Branch | Affected range |
|---|---|
| FortiWeb 7.0 | 7.0.0 – 7.0.12 |
| FortiWeb 7.2 | 7.2.0 – 7.2.12 |
| FortiWeb 7.4 | 7.4.0 – 7.4.11 |
| FortiWeb 7.6 | 7.6.0 – 7.6.6 |
| FortiWeb 8.0 | 8.0.0 – 8.0.2 |
Patch and mitigation
Fortinet advisory FG-IR-26-158 lists patched builds for each branch. If immediate upgrade is not possible, restrict management interface access to trusted management networks only and disable internet-facing admin access.
Exploitation status: unconfirmed in the wild as of initial publication.
