
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62826 is an HTTP Response Splitting vulnerability (CWE-113) in Fortinet FortiOS and FortiProxy captive portal authentication that allows an attacker who can intercept and modify a user's authentication request to inject arbitrary HTTP headers via crafted requests. Affected products include FortiOS 7.6.0–7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0–7.6.4, FortiProxy 7.4 all versions, and FortiProxy 7.2 all versions; FortiOS 8.0 is not affected. FortiPAM across multiple versions (1.0.x–1.7.x) is also listed as affected. The vulnerability was publicly disclosed on July 14, 2026, with a CVSSv3 score of 3.1 (Low) per Fortinet's advisory, though NVD assigns a base score of 4.3 (Medium) (FortiGuard Advisory).
The root cause is improper neutralization of CRLF sequences (carriage return \r and line feed \n) in HTTP headers within the captive portal authentication form, classified as CWE-113 (HTTP Response Splitting). An attacker positioned to intercept and modify a user's captive portal authentication request — a man-in-the-middle scenario — can embed CRLF sequences in crafted HTTP requests to inject arbitrary headers into the server's HTTP response. This technique can be used to manipulate response content, set malicious cookies, or facilitate cache poisoning. Exploitation requires user interaction (the victim must be performing a captive portal authentication) and network-level access to intercept the request (FortiGuard Advisory).
Successful exploitation allows an attacker to inject arbitrary HTTP headers into responses delivered to captive portal users, primarily affecting response integrity. The impact is limited to integrity (no confidentiality or availability impact per CVSS scoring), but could enable secondary attacks such as session hijacking via cookie injection, cross-site scripting via header manipulation, or cache poisoning affecting other users sharing the same proxy or cache. The attack scope is unchanged, meaning impact is confined to the targeted user's session rather than the broader system (FortiGuard Advisory).
%0d%0a or \r\n) within a header field or parameter that is reflected back in the HTTP response, such as a redirect URL or form parameter.Set-Cookie headers (session hijacking), inject a second HTTP response body (cache poisoning), or redirect the user to a phishing page (FortiGuard Advisory).%0d%0a, %0a, %0d) in header fields or query parameters; unexpected HTTP responses with duplicate or anomalous headers.Set-Cookie or Location headers in responses not matching normal application behavior.Fortinet has released patches addressing this vulnerability: upgrade FortiOS to 7.6.5 or above, and FortiProxy to 7.6.5 or above. Users on FortiOS 7.4 or 7.2 (all versions) and FortiProxy 7.4 or 7.2 (all versions) should migrate to a fixed release, as no in-branch fix is available for those branches. Fortinet recommends using the official upgrade path tool at https://docs.fortinet.com/upgrade-tool. As a network-level mitigation, deploying TLS/SSL encryption for captive portal traffic and implementing network segmentation can reduce the risk of an attacker intercepting and modifying authentication requests (FortiGuard Advisory).
The vulnerability was reported to Fortinet by Vang3lis from VARAS@IIE under responsible disclosure and was published as part of a broader Fortinet patch release addressing seven vulnerabilities across FortiOS, FortiProxy, FortiPAM, and FortiSandbox. Security news outlets including CyberSecurityNews, GBHackers, and CyberPress covered the patch release, generally characterizing CVE-2025-62826 as a lower-severity issue within the batch. No significant independent researcher commentary or social media controversy has been observed regarding this specific CVE (FortiGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."