
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26035 is a critical Improper Authentication vulnerability (CWE-287) in Fortinet FortiWeb that allows remote unauthenticated attackers to log into the FortiWeb GUI and CLI using arbitrary (random) username and password combinations. It affects FortiWeb versions 8.0.0–8.0.2, 7.6.0–7.6.6, 7.4.0–7.4.11, 7.2.0–7.2.12, and 7.0.0–7.0.12. The vulnerability was disclosed on August 12, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Fortinet PSIRT).
The vulnerability is classified as CWE-287 (Improper Authentication), meaning FortiWeb fails to adequately verify the identity of users attempting to authenticate against its management interfaces. An attacker can submit arbitrary credentials — any random username and password — and successfully authenticate to the FortiWeb GUI or CLI over the network without any prior access or privileges. No user interaction is required, and the attack complexity is low, making it trivially automatable. The flaw appears related to improper handling of RADIUS-type admin group authentication, potentially involving wildcard or bypass conditions in the authentication validation logic (GitHub Advisory, CTI Pilot).
Successful exploitation grants an unauthenticated remote attacker full administrative control over the FortiWeb web application firewall, including both the GUI and CLI. This allows the attacker to modify WAF policies, disable security rules, exfiltrate configuration data (including backend server details and SSL certificates), and potentially pivot to protected backend systems by manipulating traffic inspection rules. The complete compromise of confidentiality, integrity, and availability of the FortiWeb appliance and the assets it protects makes this a high-severity incident for any organization relying on FortiWeb for perimeter defense (GitHub Advisory, SecurityWeek).
As of the disclosure date, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is rated automatable by NVD SSVC analysis, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.51%, placing it in the 41st percentile for exploitation probability within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of reporting. No specific threat actor attribution has been made (GitHub Advisory).
https://<target>/) or connect to the CLI via SSH.Fortinet has released patches for all affected branches; organizations should upgrade to a fixed version beyond the affected ranges (i.e., FortiWeb 8.0.3+, 7.6.7+, 7.4.12+, 7.2.13+, or 7.0.13+) as referenced in the official advisory (Fortinet PSIRT). As an immediate workaround if patching cannot be applied promptly, restrict access to the FortiWeb management interfaces (GUI and CLI) to trusted administrator IP ranges using network-level access controls or firewall rules. Additionally, monitor authentication logs closely for suspicious login attempts with invalid or unrecognized credentials, and consider disabling remote management access where not operationally required (Feedly).
SecurityWeek covered the vulnerability as part of a broader Fortinet patch release addressing authentication flaws across FortiWeb and FortiManager, noting the critical severity of the authentication bypass (SecurityWeek). CyberSecurityNews and GBHackers also reported on the flaw, highlighting that unauthenticated attackers could gain access with arbitrary credentials (CyberSecurityNews). German outlet Heise.de noted the unusual nature of the vulnerability — that any credentials would work — drawing attention from the broader European security community (Heise.de). The H-ISAC issued a TLP:GREEN advisory flagging the vulnerability as high severity for healthcare sector organizations (H-ISAC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."