T

Threats

Fortinet FortiWeb Improper Authentication Vulnerability

Fortinet has published an advisory for CVE-2026-26035, an improper authentication vulnerability in FortiWeb. The vulnerability affects Remote RADIUS Type administrator authentication configured with specific, non-default settings.

An unauthenticated remote attacker may be able to log in to the FortiWeb GUI or CLI with a random username and password. Fortinet rates the vulnerability High, with a CVSS v3.1 score of 8.8. Fortinet states that exploitation is not known as of 12 August 2026.


Overview

  • CVE: CVE-2026-26035

  • Vendor: Fortinet

  • Product: FortiWeb

  • Severity: High

  • CVSS: 8.8

  • CWE: CWE-287, Improper Authentication

  • Attack type: Remote and unauthenticated

  • Publication date: 12 August 2026

  • Known exploited: No, according to the Fortinet advisory as of 12 August 2026


Affected Versions

FortiWeb 8.0

  • Affected: 8.0.0 through 8.0.2

  • Fixed: 8.0.3 or above

  • Not affected: Versions outside the affected range are marked unaffected in the CVE record.

  • Source: Fortinet PSIRT Advisory FG-IR-26-158

FortiWeb 7.6

  • Affected: 7.6.0 through 7.6.6

  • Fixed: 7.6.7 or above

  • Not affected: Versions outside the affected range are marked unaffected in the CVE record.

  • Source: Fortinet PSIRT Advisory FG-IR-26-158

FortiWeb 7.4

  • Affected: 7.4.0 through 7.4.11

  • Fixed: 7.4.12 or above

  • Not affected: Versions outside the affected range are marked unaffected in the CVE record.

  • Source: Fortinet PSIRT Advisory FG-IR-26-158

FortiWeb 7.2

  • Affected: 7.2.0 through 7.2.12

  • Fixed: 7.2.13 or above

  • Not affected: Versions outside the affected range are marked unaffected in the CVE record.

  • Source: Fortinet PSIRT Advisory FG-IR-26-158

FortiWeb 7.0


Vulnerability Breakdown

CVE-2026-26035 - Improper Authentication

  • Severity: High

  • CVSS: 8.8

  • Description: FortiWeb Remote RADIUS Type administrator authentication configured with specific, non-default settings may accept a random username and password.

  • Impact: A remote unauthenticated attacker may gain access to the FortiWeb GUI or CLI, exposing the appliance to unauthorised administrative activity.

  • Conditions: The affected configuration uses a Remote Type administrator account with RADIUS authentication and the non-default Wildcard setting enabled.

  • Notes: Fortinet reports no known exploitation as of the advisory publication date.


Mitigation

  • Upgrade FortiWeb 8.0 to version 8.0.3 or above.

  • Upgrade FortiWeb 7.6 to version 7.6.7 or above.

  • Upgrade FortiWeb 7.4 to version 7.4.12 or above.

  • Upgrade FortiWeb 7.2 to version 7.2.13 or above.

  • For the FortiWeb 7.0 branch, consult Fortinet support or the advisory before selecting a remediation release because the advisory does not identify a fixed 7.0 version.

  • If the non-default Wildcard setting is enabled, disable it for Remote Type administrator accounts.

  • In the GUI, go to System > Administrators, edit the affected Remote Type administrator account, and disable Wildcard.

  • In the CLI, edit the affected account under config system admin and run set wildcard disable.


Summary for IT Teams

  • Products: Fortinet FortiWeb

  • Threat Level: High, CVSS 8.8

  • Action Required: Identify FortiWeb appliances using Remote RADIUS Type administrator accounts with Wildcard enabled. Apply the fixed release for supported branches or disable Wildcard as an immediate workaround.


Reference


Need Help?

Secure ISS can help assess affected FortiWeb configurations, plan upgrades and validate remediation. Contact us on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.