CVE-2026-70466

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers

Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.003
23.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2026
Assigned by fortinet

Description

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-184

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiWeb
  • Fortinet · FortiOS

Credit

Fortinet is pleased to thank Rui Xi (@Cycloctane) from Beijing University of Posts and Telecommunications for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.6 or above

Something wrong here?