Skip to content
FortinetCVE-2026-70466

Fortinet FortiWeb: improper access control

Medium5.3CVE-2026-70466 · Published Aug 12, 2026 · updated Sep 8, 2026

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Fortinet advisory

Affected versions

PackageAffectedFixed in
FortiOS
Product
>= 7.6.0, <= 7.6.7No fix yet
>= 7.4.0, <= 7.4.11No fix yet
>= 7.2.0, <= 7.2.13No fix yet
>= 7.0.0, <= 7.0.19No fix yet
FortiWeb
Product
>= 8.0.0, <= 8.0.2No fix yet
>= 7.6.0, <= 7.6.5No fix yet
>= 7.4.0, <= 7.4.13No fix yet
>= 7.2.0, <= 7.2.13No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-184

More Fortinet advisories

All Fortinet
Advisory
Fortinet FortiSIEM: server-side request forgery
Low3.8Aug 12
Fortinet FortiManager: authentication bypass
High8.1Aug 12
Fortinet FortiOS: stack buffer overflow
Medium5.6Aug 12
Fortinet FortiOS: denial of service
Medium5.3Aug 12
Fortinet FortiWeb: improper authentication
Critical9.8Aug 12
Fortinet FortiClientWindows: buffer overflow
High8.1Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.