CVE-2025-48840

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unaut

Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
39.1th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.

Weakness: CWE-290

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiWeb

Credit

External

Vendor remediation

Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.9 or above

Something wrong here?