CVE-2026-39814
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.
Severity
Medium 6.2
CVSS 3.1
Exploited
Not listed
EPSS
0.001
3.7th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiWeb
Vendor remediation
Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above