Fortinet Patches Critical FortiWeb Flaw Allowing Unauthenticated Admin Logins
Fortinet has released fixes for a critical FortiWeb authentication flaw that can allow a remote, unauthenticated attacker to access the appliance’s GUI or CLI using arbitrary credentials. Tracked as CVE-2026-26035, the issue is an improper-authentication weakness, classified as CWE-287.
The vulnerability affects FortiWeb deployments that use Remote RADIUS-type administrator accounts with the non-default wildcard option enabled. In that configuration, flawed account-matching logic can accept an attacker-supplied username and password rather than requiring valid administrator credentials.
CVE-2026-26035 does not rely on password theft, credential stuffing, or traditional brute-force activity. Instead, the vulnerable authentication workflow may incorrectly match arbitrary remote users to an administrative Remote User account when the corresponding group mapping is configured in FortiWeb’s Admin User Group settings.
Fortinet Patches Critical FortiWeb Flaw
Wildcard authentication is disabled by default, reducing exposure for FortiWeb deployments that retain their original configuration.
However, enterprises can enable it to support centralized identity infrastructure or streamline administration through remote RADIUS authentication. That operational convenience creates the condition required for exploitation.
A successful compromise could hand an intruder control over a security appliance positioned directly in front of protected web applications.
Depending on the account privileges and network topology, an attacker could alter WAF policies, weaken inspection rules, review traffic-related configuration, create persistence, or use the device as a staging point for attacks against internal application infrastructure.
Affected FortiWeb Releases
The flaw affects the following FortiWeb versions:
| Release branch | Affected versions | Fixed version |
|---|---|---|
| FortiWeb 8.0 | 8.0.0–8.0.2 | 8.0.3 |
| FortiWeb 7.6 | 7.6.0–7.6.6 | 7.6.7 |
| FortiWeb 7.4 | 7.4.0–7.4.11 | 7.4.12 |
| FortiWeb 7.2 | 7.2.0–7.2.12 | 7.2.13 |
| FortiWeb 7.0 | 7.0.0–7.0.12 | Review vendor support guidance |
Fortinet’s published remediation covers the 8.0, 7.6, 7.4, and 7.2 branches. Organizations operating the legacy 7.0 line should verify the appropriate upgrade destination and supported migration path with Fortinet before making production changes.
Administrators should prioritize an upgrade to a fixed FortiWeb release after validating compatibility, backups, and the vendor-supported upgrade sequence. Where patching cannot be completed immediately, Fortinet recommends disabling wildcard authentication for every Remote Type administrator account.
Teams can review this configuration through System > Administrators in the FortiWeb GUI. From the command line, the relevant administrator configuration should be changed to disable wildcard handling, such as with set wildcard disable in the applicable system-admin context.
Additional defensive measures include:
- Restrict GUI and CLI administration to dedicated, trusted management networks.
- Remove Internet exposure from management interfaces wherever possible.
- Review Remote RADIUS administrator accounts and mapped administrative groups.
- Search authentication and administrative audit logs for unfamiliar usernames, new accounts, policy modifications, or unexpected remote-management sessions.
- Confirm that network controls prevent untrusted systems from reaching FortiWeb management services.
Fortinet had not reported active exploitation when the advisory was published. Nevertheless, the combination of a network-reachable attack path, no prerequisite authentication, and potential administrative access makes CVE-2026-26035 a high-priority remediation issue.
The disclosure is a reminder that perimeter-device risk is shaped by both patch level and configuration. Security teams should treat non-default identity integration particularly wildcard account handling and remotely accessible administration with the same urgency as critical software vulnerabilities.
No Comment! Be the first one.