Sceawere
Vulnerability Detail
CVE-2026-26035UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fortinet FortiWeb Improper Authentication Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Fortinet
- Product
- FortiWeb
- Attack Type
- Improper access control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-12T13:17:22.307Z",
"pubdate": "2026-08-12T13:17:22.307Z",
"executiveSummary": "An Improper Authentication vulnerability [CWE-287] has been identified in Fortinet FortiWeb, which may allow a remote unauthenticated attacker to successfully log into the FortiWeb GUI or CLI using arbitrary or random usernames and passwords. This critical flaw exposes administrative and management interfaces to unauthorized access, completely bypassing standard credential verification mechanisms.\nThe affected products include Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, and FortiWeb 7.0.0 through 7.0.12. Successful exploitation of this vulnerability poses severe risk implications to enterprise environments, as remote adversaries with network visibility to the management interface can achieve full unauthorized administrative sessions without possessing any prior valid credentials.\nThe attack vector is completely remote and network-based, requiring zero privileges and no user interaction. Attackers can leverage standard network protocols used by the GUI and CLI to submit crafted authentication requests containing arbitrary credentials. Given the high-privilege nature of the web management console and command-line interface, successful exploitation grants malicious actors complete administrative control over the affected FortiWeb appliance, enabling them to modify security policies, intercept traffic, manipulate configurations, and pivot deeper into the internal network infrastructure.",
"technicalDetails": "The vulnerability is classified under CWE-287 (Improper Authentication), residing within the authentication handling subsystem of the FortiWeb GUI and CLI components. The root cause stems from a flaw in how session initiation or credential validation requests are processed by the application, resulting in the failure to properly verify the authenticity and validity of provided credentials against the backend identity store.\nThe affected software versions comprise Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, and FortiWeb 7.0.0 through 7.0.12. Exploitation requires network exposure to the vulnerable management interfaces, typically accessible via HTTP/HTTPS for the GUI or SSH/telnet-based protocols for the CLI. No authentication requirements or privilege prerequisites are necessary, as the flaw specifically targets unauthenticated session establishment.\nThe step-by-step attack flow proceeds as follows. First, a remote unauthenticated attacker identifies a target FortiWeb appliance with network-accessible GUI or CLI endpoints. Second, the attacker initiates a standard authentication handshake or sends a direct login request to the management interface. Instead of supplying legitimate credentials, the attacker inputs arbitrary strings functioning as a random username and password. Due to the improper authentication logic in the validation routines, the application incorrectly evaluates the authorization state, bypasses cryptographic or database verification checks, and improperly grants a valid management session token or shell access. Finally, the attacker establishes an active session, interacting with the system under high-privilege administrative contexts.\nThe payload behavior involves interacting directly with the appliance login endpoints without triggering security alerts typically associated with brute-force attacks, as a single crafted request can suffice. The post-exploitation impact is catastrophic, as unauthorized actors gain full administrative capabilities over the FortiWeb device. This allows attackers to disable web application firewall protections, extract sensitive configuration data, deploy backdoors, and execute arbitrary commands via the CLI, undermining the confidentiality, integrity, and availability of the organization's network perimeter defense."
}