Broken access control in the RADIUS type admin group
FortiWeb RADIUS admin authentication flaw (CVSS 8.8) permits remote GUI/CLI login with random credentials under specific non-default settings.
Fortinet advisory FG-IR-26-158 describes an improper authentication flaw (CWE-287) in FortiWeb's Remote RADIUS-type admin authentication, scored CVSSv3 8.8. When the configuration uses specific non-default settings, a remote unauthenticated attacker can log into the FortiWeb GUI or CLI with a random username and password. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.
Content-Encoding WAF Evasion
FortiWeb WAF policies can be bypassed by unauthenticated attackers using crafted Content-Encoding requests (CVSS 4.8).
Fortinet disclosed an incomplete list of disallowed inputs (CWE-184) in FortiWeb's WAF, tracked as FG-IR-26-157. An unauthenticated attacker can bypass WAF policies using specifically crafted requests with crafted Content-Encoding values. The issue carries a CVSSv3 score of 4.8 and was revised on 2026-08-12. The advisory does not report active exploitation.