CVE-2026-26035
published 2026-08-12CVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through…
PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
53.1th percentile
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | 7.0.0 – 7.0.12 | — |
| fortinet | fortiweb | >= 7.2.0 < 7.2.13 | 7.2.13 |
| fortinet | fortiweb | 7.2.0 – 7.2.12 | — |
| fortinet | fortiweb | >= 7.4.0 < 7.4.12 | 7.4.12 |
| fortinet | fortiweb | 7.4.0 – 7.4.11 | — |
| fortinet | fortiweb | >= 7.6.0 < 7.6.7 | 7.6.7 |
| fortinet | fortiweb | 7.6.0 – 7.6.6 | — |
| fortinet | fortiweb | >= 8.0.0 < 8.0.3 | 8.0.3 |
| fortinet | fortiweb | 8.0.0 – 8.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiWeb up to 8.0.2 improper authentication (Nessus ID 337247)
vuldb·2026-08-18·CVSS 9.8
CVE-2026-26035 [CRITICAL] Fortinet FortiWeb up to 8.0.2 improper authentication (Nessus ID 337247)
A vulnerability classified as very critical has been found in Fortinet FortiWeb up to 7.0.12/7.2.12/7.4.11/7.6.6/8.0.2. The impacted element is an unknown function. Performing a manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-26035. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, F
ghsa_unreviewed·2026-08-12
CVE-2026-26035 [CRITICAL] CWE-287 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, F
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Fortinet
Broken access control in the RADIUS type admin group
vendor_fortinet·2026-08-12·CVSS 9.8
CVE-2026-26035 [CRITICAL] CWE-287 Broken access control in the RADIUS type admin group
FG-IR-26-158: Broken access control in the RADIUS type admin group
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
CVEs: CVE-2026-26035
CWEs: CWE-287
CVSS: 9.8 (critical)
Affected products: FortiWeb, Fortinet, Fortiweb
No detection rules found.
No public exploits indexed.
2026-08-12
Published