Sceawere

Vulnerability Detail

CVE-2026-70466UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FortiWeb Improper Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Fortinet
Product
FortiWeb
Attack Type
Improper access control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-12T13:17:24.883Z",
  "pubdate": "2026-08-12T13:17:24.883Z",
  "executiveSummary": "An incomplete list of disallowed inputs vulnerability has been identified in Fortinet FortiWeb. The flaw allows an unauthenticated or remote attacker to bypass access restrictions and achieve improper access control across multiple product versions. The vulnerability stems from insufficient input validation and sanitization mechanisms regarding restricted or disallowed input sequences within the application architecture. Affected product lines include Fortinet FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, as well as all versions of branches 7.4, 7.2, and 7.0. Successful exploitation of this security defect permits unauthorized adversaries to interact with protected resources, bypass security policy enforcement, and potentially compromise the confidentiality, integrity, and availability of the underlying web application firewall infrastructure. The risk implication is severe, as it undermines the core security enforcement boundaries maintained by the affected web application firewall devices, exposing downstream protected assets to secondary attacks. Attacker capabilities involve crafting specialized input payloads designed to evade the incomplete disallowed input filters, thereby tricking the parsing engine into accepting prohibited sequences. Exploitation requirements mandate network connectivity to the vulnerable endpoint and the construction of targeted requests that leverage the input validation discrepancy.",
  "technicalDetails": "The vulnerability is rooted in an incomplete list of disallowed inputs within Fortinet FortiWeb input filtering and parsing subsystems. When processing incoming client requests or internal administrative traffic, the vulnerable component fails to adequately enforce a comprehensive blocklist or allowlist policy for specific syntax patterns, characters, or structural tokens. Consequently, malicious payloads containing variations of disallowed inputs bypass validation checks because the parsing engine only screens for a subset of known dangerous strings or utilizes flawed regular expression matching.\nThe affected versions comprise Fortinet FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, and all iterations of versions 7.4, 7.2, and 7.0. The vulnerability resides within the request handling and policy enforcement modules responsible for input validation and access control decision-making. Depending on the specific configuration and deployment architecture, network exposure is generally present over standard management or data interfaces accessible to the attacker.\nThe step-by-step attack flow proceeds as follows: First, the adversary identifies an endpoint or functional interface within the FortiWeb appliance that relies on the flawed input validation mechanism. Second, the attacker crafts a malicious payload containing disallowed input sequences that have been slightly mutated, encoded, or formatted to evade the incomplete list of restricted entries enforced by the system. Third, the attacker transmits this crafted request over the network to the vulnerable FortiWeb instance. Fourth, the input parsing engine processes the request, incorrectly evaluates the payload as compliant due to the omission of the specific variant from the disallowed list, and passes the input downstream. Fifth, the application grants unauthorized access or executes logic that violates intended security policies, resulting in improper access control.\nPost-exploitation impact includes the potential unauthorized execution of administrative functions, exposure of sensitive system information, circumvention of configured security policies, and potential stabilization or availability issues of the security appliance itself."
}
CVE-2026-70466: FortiWeb Improper Access Control Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere