Summary
CVE-2026-26035 is an Improper Authentication vulnerability (CWE-287) affecting Fortinet FortiWeb’s Remote RADIUS Type administrator authentication. When a FortiWeb administrator account is configured with the "Wildcard" option enabled for RADIUS-based Remote authentication, a remote, unauthenticated attacker can log into the management GUI and CLI using arbitrary credentials. The flaw carries a CVSS v3.1 base score of 8.8 (High).
Technical details
- Root cause: improper validation of RADIUS-based Remote Type administrator authentication when the "Wildcard" setting is enabled for an admin account.
- Trigger conditions: the vulnerability only manifests when FortiWeb is configured with a Remote (RADIUS) administrator account that has the Wildcard option turned on — a non-default configuration.
- Attack vector: network-based, no authentication or user interaction required (AV:N, PR:N, UI:N).
- Impact: full administrative access to the FortiWeb GUI and CLI using any (arbitrary) credentials, resulting in complete loss of confidentiality, integrity, and availability of the device.
Affected software
- FortiWeb 8.0.0 through 8.0.2
- FortiWeb 7.6.0 through 7.6.6
- FortiWeb 7.4.0 through 7.4.11
- FortiWeb 7.2.0 through 7.2.12
- FortiWeb 7.0.0 through 7.0.12
Severity
- CVSS v3.1 Base Score: 8.8 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: upgrade to FortiWeb 8.0.3 or later, 7.6.7 or later, 7.4.12 or later, 7.2.13 or later, or 7.0.13 or later.
- If patching is not immediately possible: disable the "Wildcard" setting for any Remote (RADIUS) Type administrator accounts, via GUI (System > Administrators) or CLI (
set wildcard disable), which removes the exploitable condition. - Restrict administrative GUI/CLI access to trusted management networks and limit exposure of the management interface to the internet.

