Broken access control in the RADIUS type admin group
CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00
CSIRTS triage
- What
- Improper authentication in FortiWeb RADIUS type admin group allows unauthenticated remote login with arbitrary credentials under non-default configuration.
- Who is affected
- FortiWeb instances configured with remote RADIUS authentication for admin access.
- Urgency
- High urgency; CVSS 8.8 enables complete administrative access bypass.
- Action
- Update FortiWeb to patch CVE-2026-26035 and verify RADIUS authentication settings are properly configured.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiWeb
Get an email when a new FortiWeb advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-158
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-260350.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-26035 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWebncsc-nl
- high[NEW] [high] Fortinet FortiWeb: Multiple vulnerabilities enable bypass of security measurescert-bund
- unknownFortinet Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Fortinet products (August 13, 2026)cert-fr-avis
- criticalCVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 th…nvd
Recent advisories for Broken access control
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-72741: Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken functi…nvd · 2026-08-13
- mediumCVE-2026-73403: Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.nvd · 2026-08-13
- mediumCVE-2026-73401: Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.nvd · 2026-08-13
- mediumCVE-2026-73353: Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.nvd · 2026-08-13
- mediumCVE-2026-73349: Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.nvd · 2026-08-13
- mediumCVE-2026-66693: Subscriber Broken Access Control in Motors <= 1.4.113 versions.nvd · 2026-08-13
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownFGFM Authentication Weakening via CLI Configuration2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownHTTP/2 Bomb CVE-2026-499752026-08-12