High SEVERITY — Vulnerability

Broken access control in the RADIUS type admin group

CVSSv3 Score: 8.8 An Improper Authentication vulnerability in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
8.8/10
Advisory
FG-IR-26-158
Published
12 August 2026
Views
34
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 8.8 An Improper Authentication vulnerability in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Revised on 2026-08-12 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →