6 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-26035 is a high-severity improper authentication vulnerability affecting the Remote RADIUS Type Admin Authentication feature in FortiWeb.
The vulnerability occurs when a Remote Type administrator account is configured with the non-default Wildcard setting enabled. In this configuration, an unauthenticated remote attacker can authenticate to the FortiWeb GUI or CLI using arbitrary credentials.
Successful exploitation grants administrative access to the affected FortiWeb appliance. The vulnerability only impacts deployments using this specific RADIUS wildcard configuration. At the time of reporting, there are no known reports of active exploitation in the wild.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Broken Access Control in the RADIUS Type Admin Group in FortiWeb
Identifier: CVE-2026-26035
PoC or Exploitation:
CVSS Score: 8.8 (High, CVSS v3.1)
Update / Patch:
- FortiWeb 8.0.0 through 8.0.2
- FortiWeb 7.6.0 through 7.6.6
- FortiWeb 7.4.0 through 7.4.11
- FortiWeb 7.2.0 through 7.2.12
- FortiWeb 8.0.3 or above
- FortiWeb 7.6.7 or above
- FortiWeb 7.4.12 or above
- FortiWeb 7.2.13 or above
Description:
Mitigation Recommendation: