T
Threats
Fortinet FortiWeb Improper Authentication Vulnerability
Fortinet has published an advisory for CVE-2026-26035, an improper authentication vulnerability in FortiWeb. The vulnerability affects Remote RADIUS Type administrator authentication configured with specific, non-default settings.
An unauthenticated remote attacker may be able to log in to the FortiWeb GUI or CLI with a random username and password. Fortinet rates the vulnerability High, with a CVSS v3.1 score of 8.8. Fortinet states that exploitation is not known as of 12 August 2026.
Overview
CVE: CVE-2026-26035
Vendor: Fortinet
Product: FortiWeb
Severity: High
CVSS: 8.8
CWE: CWE-287, Improper Authentication
Attack type: Remote and unauthenticated
Publication date: 12 August 2026
Known exploited: No, according to the Fortinet advisory as of 12 August 2026
Affected Versions
FortiWeb 8.0
Affected: 8.0.0 through 8.0.2
Fixed: 8.0.3 or above
Not affected: Versions outside the affected range are marked unaffected in the CVE record.
FortiWeb 7.6
Affected: 7.6.0 through 7.6.6
Fixed: 7.6.7 or above
Not affected: Versions outside the affected range are marked unaffected in the CVE record.
FortiWeb 7.4
Affected: 7.4.0 through 7.4.11
Fixed: 7.4.12 or above
Not affected: Versions outside the affected range are marked unaffected in the CVE record.
FortiWeb 7.2
Affected: 7.2.0 through 7.2.12
Fixed: 7.2.13 or above
Not affected: Versions outside the affected range are marked unaffected in the CVE record.
FortiWeb 7.0
Affected: 7.0.0 through 7.0.12
Fixed: Fortinet has not specified an exact fixed version for the 7.0 branch as of 12 August 2026.
Not affected: Versions outside the affected range are marked unaffected in the CVE record.
Source: CVE.org Record for CVE-2026-26035 and Fortinet PSIRT Advisory FG-IR-26-158
Vulnerability Breakdown
CVE-2026-26035 - Improper Authentication
Severity: High
CVSS: 8.8
Description: FortiWeb Remote RADIUS Type administrator authentication configured with specific, non-default settings may accept a random username and password.
Impact: A remote unauthenticated attacker may gain access to the FortiWeb GUI or CLI, exposing the appliance to unauthorised administrative activity.
Conditions: The affected configuration uses a Remote Type administrator account with RADIUS authentication and the non-default Wildcard setting enabled.
Notes: Fortinet reports no known exploitation as of the advisory publication date.
Mitigation
Upgrade FortiWeb 8.0 to version 8.0.3 or above.
Upgrade FortiWeb 7.6 to version 7.6.7 or above.
Upgrade FortiWeb 7.4 to version 7.4.12 or above.
Upgrade FortiWeb 7.2 to version 7.2.13 or above.
For the FortiWeb 7.0 branch, consult Fortinet support or the advisory before selecting a remediation release because the advisory does not identify a fixed 7.0 version.
If the non-default Wildcard setting is enabled, disable it for Remote Type administrator accounts.
In the GUI, go to System > Administrators, edit the affected Remote Type administrator account, and disable Wildcard.
In the CLI, edit the affected account under
config system adminand runset wildcard disable.
Summary for IT Teams
Products: Fortinet FortiWeb
Threat Level: High, CVSS 8.8
Action Required: Identify FortiWeb appliances using Remote RADIUS Type administrator accounts with Wildcard enabled. Apply the fixed release for supported branches or disable Wildcard as an immediate workaround.
Reference
Need Help?
Secure ISS can help assess affected FortiWeb configurations, plan upgrades and validate remediation. Contact us on 1300 769 460.

