About:
CVE-2026-26035 is a high-severity improper authentication vulnerability affecting the Remote RADIUS Type Admin Authentication feature in FortiWeb.
The vulnerability occurs when a Remote Type administrator account is configured with the non-default Wildcard setting enabled. In this configuration, an unauthenticated remote attacker can authenticate to the FortiWeb GUI or CLI using arbitrary credentials.
Successful exploitation grants administrative access to the affected FortiWeb appliance. The vulnerability only impacts deployments using this specific RADIUS wildcard configuration. At the time of reporting, there are no known reports of active exploitation in the wild.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Broken Access Control in the RADIUS Type Admin Group in FortiWeb
Identifier: CVE-2026-26035
PoC or Exploitation:
Not known to be exploited.
CVSS Score: 8.8 (High, CVSS v3.1)
Update / Patch:
Fortinet has released fixed versions addressing this vulnerability.
Affected versions include:
- FortiWeb 8.0.0 through 8.0.2
- FortiWeb 7.6.0 through 7.6.6
- FortiWeb 7.4.0 through 7.4.11
- FortiWeb 7.2.0 through 7.2.12
Fixed versions include:
- FortiWeb 8.0.3 or above
- FortiWeb 7.6.7 or above
- FortiWeb 7.4.12 or above
- FortiWeb 7.2.13 or above
A workaround is available if immediate patching is not possible:
Disable the Wildcard setting on any Remote Type administrator account.
Fortinet advisory and patch guidance:
Description:
CVE-2026-26035 is an improper authentication vulnerability in FortiWeb's Remote RADIUS Type Admin Authentication feature.
When a Remote Type administrator account is configured with the Wildcard setting enabled, which is a non-default configuration, a remote unauthenticated attacker can log into the FortiWeb GUI or CLI using a random username and password.
Impact is limited to accounts using this specific RADIUS wildcard configuration. Successful exploitation grants administrative access to the FortiWeb GUI and CLI.
Mitigation Recommendation:
Apply the applicable fixed version for your FortiWeb release as soon as operationally feasible.
If immediate patching is not possible, apply the vendor's workaround immediately.
Audit all FortiWeb Remote Type administrator accounts to identify any with the Wildcard setting enabled.
Review administrative login logs on FortiWeb appliances for unexpected or unrecognized usernames authenticating through Remote Type accounts which may indicate attempted exploitation.