fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-26-157 CVE-2026-70466
MEDIUM
Fortinet FortiWeb Incomplete List of Disallowed Inputs Leading to Improper Access Control
Record summary
CVE-2026-70466 has a selected CVSS score of 4.8 (medium).
Description
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FortiOSBrowse Fortinet / FortiOSDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.7 | affected |
| 7.4.0 to ≤ 7.4.11 | affected | ||
| 7.2.0 to ≤ 7.2.13 | affected | ||
| 7.0.0 to ≤ 7.0.19 | affected | ||
| 6.4.0 to ≤ 6.4.16 | affected | ||
FortiWebBrowse Fortinet / FortiWebDefault status: unaffected | CVE List | 8.0.0 to ≤ 8.0.2 | affected |
| 7.6.0 to ≤ 7.6.5 | affected | ||
| 7.4.0 to ≤ 7.4.13 | affected | ||
| 7.2.0 to ≤ 7.2.13 | affected | ||
| 7.0.0 to ≤ 7.0.12 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70466