
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-70466 is an incomplete list of disallowed inputs vulnerability (CWE-184) in Fortinet FortiWeb that may allow unauthenticated attackers to bypass access control restrictions. It affects FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, and all versions of 7.4, 7.2, and 7.0. The vulnerability was published on August 12, 2026, with a patch available from Fortinet. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Fortinet PSIRT).
The root cause is classified as CWE-184 (Incomplete List of Disallowed Inputs), where FortiWeb's protection mechanism relies on a blocklist of inputs that is insufficiently comprehensive, allowing certain malicious inputs to bypass validation. An unauthenticated remote attacker can exploit this over the network with low complexity and no user interaction required, potentially gaining improper access to protected resources or functionality. The specific attack vector details (i.e., the exact endpoint or parameter targeted) have not been publicly disclosed in available advisories. Associated attack patterns include double encoding (CAPEC-120), Unicode encoding bypass (CAPEC-71), and exploiting multiple input interpretation layers (CAPEC-43) (GitHub Advisory, Fortinet PSIRT).
Successful exploitation allows an unauthenticated network attacker to bypass authorization controls and gain improper access to protected resources or functionality within FortiWeb. The integrity impact is rated low, with no direct confidentiality or availability impact per the CVSS scoring. However, as FortiWeb is a web application firewall, an authorization bypass could undermine the security posture of protected backend applications and potentially expose them to further attack (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication. The EPSS score is approximately 0.309% (23rd percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
Fortinet has released patches addressing this vulnerability; users should upgrade FortiWeb to versions beyond 8.0.2 (for the 8.0.x branch) or beyond 7.6.5 (for the 7.6.x branch), and apply the latest available updates for 7.4, 7.2, and 7.0 branches. As a network-level workaround, administrators should restrict access to FortiWeb administration interfaces and sensitive functions using firewall rules or access control lists. Monitoring FortiWeb logs for suspicious authorization bypass attempts is also recommended (Fortinet PSIRT, GitHub Advisory).
Security news outlets including CyberSecurityNews, GBHackers, and Cryptika covered this vulnerability as part of broader reporting on Fortinet patching multiple authentication-related vulnerabilities in FortiWeb, FortiManager, and FortiClient in August 2026. Coverage generally characterized the issue as moderate severity with no active exploitation observed. The CTI Pilot community noted the vulnerability in the context of a FortiWeb RADIUS wildcard bypass and FortiManager FGFM advisory batch (CyberSecurityNews, GBHackers, Cryptika).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."