CVE-2026-26035
Description
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
In plain language
AI Act nowFortinet FortiWeb has a login-check flaw that lets an attacker access the admin interface with any username and password—so a typical small business should treat this as urgent if FortiWeb’s management console is reachable from the network.
Fortinet FortiWeb is vulnerable to an Improper Authentication issue (CWE-287) that allows unauthenticated remote attackers to bypass login checks and gain full administrative control over the device by attempting management-console access with arbitrary credentials.
What to do now
- Check your FortiWeb version and whether the FortiWeb management interface (GUI and/or CLI) is reachable from the internet or other external networks.
- If you are on FortiWeb 8.0.0–8.0.2, upgrade to FortiWeb 8.0.3 or above.
- If you are on FortiWeb 7.6.0–7.6.6, upgrade to FortiWeb 7.6.7 or above.
- If you are on FortiWeb 7.4.0–7.4.11, upgrade to FortiWeb 7.4.12 or above.
- If you are on FortiWeb 7.2.0–7.2.12 or 7.0.0–7.0.12, upgrade to the upcoming FortiWeb 7.2.13 or 7.0.13 or above as directed by Fortinet.
- If you cannot upgrade immediately, restrict network access so the management interface is not reachable from untrusted networks (for example, block external access and allow only from your admin network).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-26035 and every CVE in our database. Create a free account — no credit card required.
Create Free Account