
PEACH
Un cadre d’isolation des locataires
CVE-2026-70466 is an incomplete list of disallowed inputs vulnerability (CWE-184) in Fortinet FortiWeb that may allow unauthenticated attackers to bypass access control restrictions. It affects FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, and all versions of 7.4, 7.2, and 7.0. The vulnerability was published on August 12, 2026, with a patch available from Fortinet. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Fortinet PSIRT).
The root cause is classified as CWE-184 (Incomplete List of Disallowed Inputs), where FortiWeb's protection mechanism relies on a blocklist of inputs that is insufficiently comprehensive, allowing certain malicious inputs to bypass validation. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction required, potentially gaining improper access to protected resources or functionality. The specific attack vector details (i.e., the exact endpoint or parameter targeted) have not been publicly disclosed in available advisories. Associated attack patterns include double encoding (CAPEC-120), Unicode encoding bypass (CAPEC-71), and exploiting multiple input interpretation layers (CAPEC-43) (GitHub Advisory, Fortinet PSIRT).
Successful exploitation allows an unauthenticated network attacker to bypass authorization controls and gain improper access to protected resources or functionality within FortiWeb. The integrity impact is rated low, with no direct confidentiality or availability impact per the CVSS scoring. However, as FortiWeb is a web application firewall, an authorization bypass could undermine the security posture of protected backend applications and potentially expose them to further attack (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication. The EPSS score is approximately 0.309% (23rd percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
Fortinet has released patches addressing this vulnerability; users should upgrade FortiWeb to versions beyond 8.0.2 (for the 8.0.x branch) or beyond 7.6.5 (for the 7.6.x branch), and apply the latest available updates for 7.4, 7.2, and 7.0 branches. As a network-level workaround, administrators should restrict access to FortiWeb administration interfaces and sensitive functions using firewall rules or access control lists. Monitoring FortiWeb logs for suspicious authorization bypass attempts is also recommended (Fortinet PSIRT, GitHub Advisory).
Security news outlets including CyberSecurityNews, GBHackers, and Cryptika covered this vulnerability as part of broader reporting on Fortinet patching multiple authentication-related vulnerabilities in FortiWeb, FortiManager, and FortiClient in August 2026. Coverage generally characterized the issue as moderate severity with no active exploitation observed. The CTI Pilot community noted the vulnerability in the context of a FortiWeb RADIUS wildcard bypass and FortiManager FGFM advisory batch (CyberSecurityNews, GBHackers, Cryptika).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."