CVE-2026-70466
FortiOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-70466 is an incomplete list of disallowed inputs vulnerability (CWE-184) in Fortinet FortiWeb that may allow unauthenticated attackers to bypass access control restrictions. It affects FortiWeb versions 8.0.0–8.0.2, 7.6.0–7.6.5, 7.4.x (all versions), 7.2.x (all versions), and 7.0.x (all versions). The vulnerability was published on August 12, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Fortinet PSIRT).

Detalhes técnicos

The vulnerability is classified as CWE-184 (Incomplete List of Disallowed Inputs), meaning FortiWeb's protection mechanism relies on a blocklist of disallowed inputs that is insufficiently comprehensive, allowing certain malicious inputs to bypass validation and circumvent access controls. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it automatable. The specific attack vector details (i.e., the exact parameter or endpoint targeted) have not been publicly disclosed in available advisories. Associated attack patterns include double encoding (CAPEC-120), argument injection (CAPEC-6), and using Unicode encoding to bypass validation logic (CAPEC-71) (GitHub Advisory, Fortinet PSIRT).

Impacto

Successful exploitation allows an unauthenticated remote attacker to bypass authorization controls and gain improper access to protected resources or functionality within FortiWeb. The integrity impact is rated low, with no direct confidentiality or availability impact per the CVSS scoring. However, as FortiWeb is a web application firewall, unauthorized access to its management or policy functions could undermine the security posture of protected web applications and potentially facilitate further attacks against downstream assets (GitHub Advisory, Feedly).

Exploração

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.309% (24th percentile), indicating a low near-term exploitation probability. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted at scale if a PoC were to emerge. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Fortinet PSIRT).

Mitigação e soluções alternativas

Fortinet has released patches addressing this vulnerability; users should upgrade FortiWeb to a version beyond the affected ranges (i.e., beyond 8.0.2, 7.6.5, 7.4.x, 7.2.x, and 7.0.x). As an interim measure, administrators should implement network-level access controls to restrict access to FortiWeb administration interfaces and sensitive functions. Monitoring FortiWeb logs for suspicious authorization bypass attempts is also recommended (Fortinet PSIRT, GitHub Advisory).

Reações da comunidade

Security news outlets including CyberSecurityNews, GBHackers, and Cryptika covered this vulnerability as part of broader reporting on Fortinet patching multiple authentication-related vulnerabilities in FortiWeb, FortiManager, and FortiClient in August 2026. Coverage generally characterized the patch batch as routine but noteworthy given Fortinet's prominence in enterprise network security. No significant researcher controversy or social media debate was observed around this specific CVE (CyberSecurityNews, GBHackers, Cryptika).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado FortiOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-71407MEDIUM5.6
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimAug 12, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimJul 14, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NãoSimAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NãoSimAug 12, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NãoSimJul 14, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades