Medium SEVERITY — Vulnerability

Content-Encoding WAF Evasion

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
4.8/10
Advisory
FG-IR-26-157
Published
12 August 2026
Views
41
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →