
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30897 is a stack-based buffer overflow vulnerability (CWE-121) in Fortinet FortiWeb's API component that may allow a remote authenticated attacker to execute arbitrary code or commands via crafted HTTP requests. The vulnerability affects FortiWeb 8.0.0–8.0.3, 7.6.0–7.6.6, 7.4.0–7.4.11, and all versions of 7.2 and 7.0. It was internally discovered and reported by David Maciejak of Fortinet's Product Security team, with initial publication on March 10, 2026. The CVSS v3.1 base score is 6.6 (Medium), though the Fortinet advisory lists a CVSSv3 score of 5.9 (Medium) (Fortinet PSIRT, Feedly).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in the FortiWeb API component. An attacker must be remotely authenticated with high-level privileges and capable of bypassing stack protection mechanisms (e.g., stack canaries) and ASLR to successfully exploit the flaw. Exploitation is achieved by sending specially crafted HTTP requests that trigger the overflow condition, potentially redirecting execution flow to attacker-controlled code. No public proof-of-concept exploit code has been identified as of the time of reporting (Fortinet PSIRT, Feedly).
Successful exploitation could result in complete compromise of the affected FortiWeb web application firewall, with high impacts to confidentiality, integrity, and availability. An attacker achieving arbitrary code execution on the FortiWeb appliance could access sensitive data traversing the WAF, modify security policies, disable protections for backend applications, and potentially use the compromised appliance as a pivot point for lateral movement into protected network segments (Fortinet PSIRT, Feedly).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the reporting date. The Fortinet advisory confirms the vulnerability is not known to be exploited ("Known Exploited: No"). The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges and the ability to bypass both stack protection and ASLR, significantly raising the bar for successful attacks (Fortinet PSIRT, Feedly).
Fortinet has released patched versions to address this vulnerability. Organizations should upgrade to the following fixed releases: FortiWeb 8.0.4 or later, FortiWeb 7.6.7 or later, or FortiWeb 7.4.12 or later. For FortiWeb 7.2 and 7.0 (all versions), no direct patch is available — users must migrate to a supported fixed release. As interim mitigations, restrict remote administrative access to FortiWeb management interfaces to trusted networks only, enforce least-privilege access controls for authenticated users, and monitor HTTP traffic for anomalous patterns targeting the API. Ensure OS-level stack protection and ASLR are enabled where applicable (Fortinet PSIRT).
Coverage of CVE-2026-30897 has been limited, consistent with its medium severity rating and lack of active exploitation. A network engineer patching guide published in March 2026 included this CVE alongside other Fortinet and Ivanti vulnerabilities disclosed that month, indicating awareness within the practitioner community (FirstPassLab). No significant vendor statements beyond the official Fortinet PSIRT advisory or notable researcher commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."