Executive brief
A security vulnerability exists in the captive portal authentication system of Fortinet firewalls and web proxies. An attacker who can intercept a user's login request could inject malicious data into the web response, potentially leading to session manipulation or further web-based attacks. This issue primarily affects organizations using captive portals for guest or user network access.
Technical details
An HTTP Response Splitting vulnerability (CWE-113) exists in the captive portal authentication component of FortiOS and FortiProxy. The flaw is caused by improper neutralization of CRLF sequences in HTTP headers. An attacker who can perform a Man-in-the-Middle (MitM) interception of a user's authentication request can modify the request to inject arbitrary headers into the resulting HTTP response. This requires the attacker to be in a position to intercept and modify traffic (AC:H) and involves user interaction (UI:R). Fortinet recommends upgrading to FortiOS/FortiProxy version 7.6.5 or migrating from the affected 7.2 and 7.4 branches.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: FG-IR-26-153 published