Junglewise Threat Intelligence

CVE-2025-62826: Fortinet FortiOS and FortiProxy HTTP Response Splitting in captive portal

CVE-2025-62826 · Severity: low · CVSS 3.1 · Published 2026-07-14

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A security vulnerability exists in the captive portal authentication system of Fortinet firewalls and web proxies. An attacker who can intercept a user's login request could inject malicious data into the web response, potentially leading to session manipulation or further web-based attacks. This issue primarily affects organizations using captive portals for guest or user network access.

Technical details

An HTTP Response Splitting vulnerability (CWE-113) exists in the captive portal authentication component of FortiOS and FortiProxy. The flaw is caused by improper neutralization of CRLF sequences in HTTP headers. An attacker who can perform a Man-in-the-Middle (MitM) interception of a user's authentication request can modify the request to inject arbitrary headers into the resulting HTTP response. This requires the attacker to be in a position to intercept and modify traffic (AC:H) and involves user interaction (UI:R). Fortinet recommends upgrading to FortiOS/FortiProxy version 7.6.5 or migrating from the affected 7.2 and 7.4 branches.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: FG-IR-26-153 published

References

Related threats