Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-26035

FortiWeb Authentication Bypass Allows Unauthenticated Login

An improper authentication flaw in FortiWeb lets remote unauthenticated attackers log in with any credentials. Affects versions 7.0.x through 8.0.x; patch available.

cat cve-2026-26035.json
Vendor
Fortinet
Product
FortiWeb
CVSS
9.8
EPSS (exploit probability)
N/A
Status
patched
Published

Improper authentication (CWE-287) in Fortinet FortiWeb allows a remote unauthenticated attacker to log in to the management GUI or CLI using any arbitrary username and password combination.

Affected versions

BranchAffected range
FortiWeb 7.07.0.0 – 7.0.12
FortiWeb 7.27.2.0 – 7.2.12
FortiWeb 7.47.4.0 – 7.4.11
FortiWeb 7.67.6.0 – 7.6.6
FortiWeb 8.08.0.0 – 8.0.2

Patch and mitigation

Fortinet advisory FG-IR-26-158 lists patched builds for each branch. If immediate upgrade is not possible, restrict management interface access to trusted management networks only and disable internet-facing admin access.

Exploitation status: unconfirmed in the wild as of initial publication.