
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24017 is an Improper Control of Interaction Frequency vulnerability (CWE-799) in Fortinet FortiWeb that allows a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests, enabling brute-force attacks against admin logins. Affected versions include FortiWeb 8.0.0–8.0.2, 7.6.0–7.6.5, 7.4.0–7.4.10, 7.2.0–7.2.11, and 7.0.0–7.0.11; FortiAppSec Cloud is not impacted. The vulnerability was internally discovered and reported by Yanmin Ji of the Fortinet Development team, with initial publication on March 10, 2026. It carries a CVSSv3 score of 7.3–8.1 (High) depending on the scoring source (FortiGuard Advisory, Feedly).
The root cause is classified as CWE-799 (Improper Control of Interaction Frequency), meaning the FortiWeb GUI fails to properly enforce rate-limiting controls on authentication attempts when receiving specially crafted requests. An attacker can craft HTTP requests that circumvent the mechanism designed to throttle or block repeated login attempts, effectively removing the brute-force protection on the administrative interface. No authentication or user interaction is required to initiate the attack, and it is conducted entirely over the network. The success of exploitation is contingent on the attacker's available computational resources and the complexity of the target account's password (FortiGuard Advisory).
Successful exploitation allows an attacker to conduct unrestricted brute-force attacks against FortiWeb's administrative authentication interface, potentially gaining unauthorized administrative access. A compromised FortiWeb appliance could allow an attacker to modify web application firewall (WAF) security policies, expose backend application traffic, and pivot to protected backend systems. The confidentiality, integrity, and availability of both the FortiWeb appliance and the systems it protects are at risk (FortiGuard Advisory, Feedly).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (FortiGuard Advisory, Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.077%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported.
Fortinet has released patched versions addressing this vulnerability; administrators should upgrade to FortiWeb 8.0.3 or above, 7.6.6 or above, 7.4.11 or above, 7.2.12 or above, or 7.0.12 or above (FortiGuard Advisory). As interim mitigations, organizations should restrict access to the FortiWeb administrative interface to trusted IP addresses only using network-level access controls or firewall rules. Enforcing strong, complex passwords for all administrative accounts increases the difficulty of a successful brute-force attack. Enabling multi-factor authentication (MFA) where supported provides an additional layer of protection against credential-based attacks.
The Belgian Centre for Cybersecurity (CCB) issued a warning advising organizations to patch immediately following Fortinet's disclosure of 22 vulnerabilities across multiple products, including CVE-2026-24017 (CCB Advisory). Austria's CERT.at also flagged the vulnerability in its daily threat digest (CERT.at). Singapore's CSA published an alert referencing the issue (CSA Alert). Community and media coverage has been moderate, consistent with a high-severity but not yet actively exploited Fortinet advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."