CVE-2025-48840
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unaut
Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
39.1th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet
Description
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.
Weakness: CWE-290
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiWeb
Credit
External
Vendor remediation
Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.9 or above