Security News

Cybersecurity news aggregator

🛡️
HIGH Vulnerabilities Fortinet PSIRT

Broken access control in the RADIUS type admin group

An improper authentication vulnerability (CVE-2026-26035, CVSSv3 8.8) in FortiWeb allows unauthenticated remote attackers to log into the GUI/CLI with random credentials when a Remote RADIUS Type Admin Authentication is configured with a specific, non-default "Wildcard" setting enabled. Affected versions include FortiWeb 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, and 7.2.0 through 7.2.12, which should be upgraded to versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13 respectively. As an immediate workaround, administrators should disable the Wildcard option for any Remote Type administrator account where it is enabled.
Read Full Article →

PSIRT Broken access control in the RADIUS type admin group Summary An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Version Affected Solution FortiWeb 8.0 8.0.0 through 8.0.2 Upgrade to 8.0.3 or above FortiWeb 7.6 7.6.0 through 7.6.6 Upgrade to 7.6.7 or above FortiWeb 7.4 7.4.0 through 7.4.11 Upgrade to 7.4.12 or above FortiWeb 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above Workaround If enabled (non default), disable the Wildcard setting for the Administrators In the GUI: Go to System > Administrators, edit the Remote Type administrator account that has the Wildcard option enabled, and disable the Wildcard option. In the CLI: config system admin edit < Remote type administrator account > set wildcard disable next end Acknowledgement Internally discovered as part of a Fortinet audit. Timeline 2026-08-12: Initial publication References https://docs.fortinet.com/document/fortiweb/8.0.2/cli-reference/810797/system-admin https://docs.fortinet.com/document/fortiweb/8.0.3/administration-guide/286471/administrators IR Number FG-IR-26-158 Published Date Aug 12, 2026 Component CLI Severity High Discovered Internal Attack Type Unauthenticated Known Exploited No CVSSv3 Score 8.8 Impact Improper access control CVE ID CVE-2026-26035 Download CVRF CSAF

Share this article