Executive brief
FortiWeb is a web application firewall designed to protect business applications from cyberattacks. A security flaw in its management interface could allow an administrator with high-level privileges to execute unauthorized commands on the system. While this requires existing administrative access, it could be used by a malicious insider or a compromised admin account to take full control of the security appliance.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the FortiWeb CGI daemon within the administrative GUI component. The flaw is triggered by processing specially crafted HTTP requests sent to the management interface. An attacker must have high-level administrative privileges (PR:H) to exploit this vulnerability. Successful exploitation allows for arbitrary code execution or command injection with the privileges of the affected daemon. Fortinet has released patches in versions 8.0.4, 7.6.7, and 7.4.12 to address this issue.
Affected products
- Fortinet FortiWeb 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11
Timeline
- 2026-04-14: disclosed
- 2026-04-15: advisory: Initial publication of FG-IR-26-127