CVE-2026-70466
published 2026-08-12CVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.29%
22.3th percentile
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.19 | — |
| fortinet | fortios | 7.2.0 – 7.2.13 | — |
| fortinet | fortios | 7.4.0 – 7.4.11 | — |
| fortinet | fortios | 7.6.0 – 7.6.7 | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.0.0 < 7.6.6 | 7.6.6 |
| fortinet | fortiweb | 7.0.0 – 7.0.12 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.13 | — |
| fortinet | fortiweb | 7.4.0 – 7.4.13 | — |
| fortinet | fortiweb | 7.6.0 – 7.6.5 | — |
| fortinet | fortiweb | >= 8.0.0 < 8.0.3 | 8.0.3 |
| fortinet | fortiweb | 8.0.0 – 8.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Content-Encoding WAF Evasion
vendor_fortinet·2026-08-12·CVSS 5.3
CVE-2026-70466 [MEDIUM] CWE-184 Content-Encoding WAF Evasion
FG-IR-26-157: Content-Encoding WAF Evasion
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via
CVEs: CVE-2026-70466
CWEs: CWE-184
CVSS: 5.3 (medium)
Affected products: FortiWeb, Fortinet
GHSA
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers
ghsa_unreviewed·2026-08-12
CVE-2026-70466 [MEDIUM] CWE-184 A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published