ZeroHour
Fortinet PSIRTpublished ()ingested

Broken access control in the RADIUS type admin group

highAdvisoryimportance 48
AI summary · glm-5.3-flash

FortiWeb RADIUS admin authentication flaw (CVSS 8.8) permits remote GUI/CLI login with random credentials under specific non-default settings.

Fortinet advisory FG-IR-26-158 describes an improper authentication flaw (CWE-287) in FortiWeb's Remote RADIUS-type admin authentication, scored CVSSv3 8.8. When the configuration uses specific non-default settings, a remote unauthenticated attacker can log into the FortiWeb GUI or CLI with a random username and password. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.

  • Improper authentication (CWE-287) in FortiWeb RADIUS admin group
  • Random username and password grant GUI/CLI admin access
  • Applies only with specific non-default settings; CVSSv3 8.8
VendorsFortinet
ProductsFortiWeb
OrganizationsFortinet
Full article

CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.