Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-26035

FortiWeb Authentication Bypass Allows Unauthenticated Login

An improper authentication flaw in FortiWeb lets remote unauthenticated attackers log in with any credentials. Affects versions 7.0.x through 8.0.x; patch available.

cat cve-2026-26035.json
Vendor
Fortinet
Product
FortiWeb
CVSS
9.8
EPSS (exploit probability)
0.7%
Status
patched
Published

Improper authentication (CWE-287) in Fortinet FortiWeb allows a remote unauthenticated attacker to log in to the management GUI or CLI using any arbitrary username and password combination.

Affected versions

Branch Affected range
FortiWeb 7.0 7.0.0 – 7.0.12
FortiWeb 7.2 7.2.0 – 7.2.12
FortiWeb 7.4 7.4.0 – 7.4.11
FortiWeb 7.6 7.6.0 – 7.6.6
FortiWeb 8.0 8.0.0 – 8.0.2

Patch and mitigation

Fortinet advisory FG-IR-26-158 lists patched builds for each branch. If immediate upgrade is not possible, restrict management interface access to trusted management networks only and disable internet-facing admin access.

Exploitation status: unconfirmed in the wild as of initial publication.