All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-26035
CRITICALpublished 2026-08-12 13:17 UTC · 14 hours ago · modified 2026-08-12 14:17 UTC
9.8
CVSS / 10
// description
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
// weaknesses (CWE)
- CWE-287