Fortinet FortiWeb Critical Auth Bypass Flaw Patched

Fortinet patches critical auth bypass in FortiWeb WAF (CVE-2026-26035)

CRITICAL
August 14, 2026
4m read
VulnerabilityPatch Management

Related Entities

Organizations

Products & Tech

FortiWebFortiManager

CVE Identifiers

Full Report

Executive Summary

Fortinet has released security updates to address multiple vulnerabilities in its FortiWeb Web Application Firewall (WAF) and FortiManager platforms. The most severe of these is CVE-2026-26035, a critical authentication bypass vulnerability in FortiWeb. This flaw allows a remote, unauthenticated attacker to gain administrative access to the device's GUI using any username and password. The vulnerability is only exploitable if a specific, non-default configuration—an 'admin wildcard'—is enabled. However, for any organization using this setting, the risk of complete device takeover is critical. Fortinet has urged all customers to apply the patches and audit their configurations immediately.


Vulnerability Details

CVE-2026-26035: Critical Authentication Bypass This vulnerability exists in the management interface of the FortiWeb WAF. The flaw is triggered when an administrator has configured a wildcard administrator account (e.g., *) to allow any user from a trusted subnet to log in. Due to a flaw in the authentication logic, an attacker from any location (not just the trusted subnet) can abuse this configuration to log in with any password.

  • Attack Vector: Remote/Network
  • Complexity: Low
  • Privileges Required: None
  • Prerequisites: The 'admin wildcard' setting must be enabled on the target FortiWeb device. This is a non-default setting.

Other patched vulnerabilities include:

  • CVE-2026-49975: Authentication bypass in FortiWeb.
  • CVE-2026-70465: Authentication bypass in FortiManager.
  • CVE-2026-70468: Authentication bypass in FortiManager.

Affected Systems

  • FortiWeb: Specific versions are affected by CVE-2026-26035 and CVE-2026-49975. Customers should consult the Fortinet PSIRT advisory for the exact version list.
  • FortiManager: Specific versions are affected by CVE-2026-70465 and CVE-2026-70468.

Exploitation Status

There is no public information about active exploitation of these vulnerabilities. However, Fortinet security appliances are high-value targets for threat actors, as they are gateways to internal networks. The public disclosure of these flaws, especially the critical authentication bypass, means that exploitation attempts are likely to follow.

Impact Assessment

Successful exploitation of CVE-2026-26035 would grant an attacker full administrative control over the FortiWeb WAF. This would allow the attacker to:

  • Disable security policies, rendering web applications unprotected.
  • Modify traffic routing rules to redirect users to malicious sites (T1657 - Financial Theft).
  • Decrypt and inspect sensitive SSL/TLS traffic passing through the WAF.
  • Use the compromised WAF as a pivot point to attack the internal network (T1190 - Exploit Public-Facing Application).

Compromise of a FortiManager instance could be even more catastrophic, as it could allow an attacker to push malicious configurations to all managed Fortinet devices simultaneously.

Cyber Observables — Hunting Hints

The following patterns can help identify misconfigurations or exploitation attempts:

Type
Configuration Check
Value
config system admin
Description
On FortiWeb, check for a wildcard entry (edit *) in the admin configuration. This indicates the vulnerable setting is enabled.
Type
Log Source
Value
FortiWeb Event Logs
Description
Look for successful administrative logins from unexpected or untrusted IP addresses.
Type
Log Source
Value
FortiManager Event Logs
Description
Audit for successful logins from unknown sources or suspicious configuration changes being pushed to managed devices.

Detection Methods

  • Configuration Audit: The most important detection step is to audit your FortiWeb configuration to check for the presence of the 'admin wildcard' setting. This can be done via the CLI (show system admin) or the GUI.
  • Log Review: Regularly review authentication logs on FortiWeb and FortiManager devices. Ingest these logs into a SIEM and create alerts for successful administrative logins from IPs outside of your organization's known ranges. This aligns with D3FEND's Authentication Event Thresholding (D3-ANET).

Remediation Steps

  1. Patch: Apply the security updates provided by Fortinet for all affected products immediately. This is the primary and most effective remediation. This is an application of Software Update (D3-SU).
  2. Disable Wildcard Admin: As a critical immediate step, and as a general security best practice, disable the 'admin wildcard' setting on all FortiWeb devices. Administrative access should be granted only through explicitly defined, named accounts. This is a form of Application Configuration Hardening (D3-ACH).
  3. Restrict Management Access: Limit access to the FortiWeb and FortiManager management interfaces to a dedicated, secure management network. Do not expose these interfaces to the internet.
  4. Enforce MFA: Enable multi-factor authentication for all administrative accounts on Fortinet devices to provide an additional layer of security.

Timeline of Events

1
August 14, 2026
This article was published

MITRE ATT&CK Mitigations

Apply the security patches released by Fortinet for the affected products.

Mapped D3FEND Techniques:

Audit device configurations and disable insecure, non-default settings like the 'admin wildcard'.

Mapped D3FEND Techniques:

Restrict network access to management interfaces, ensuring they are not exposed to the internet.

Mapped D3FEND Techniques:

Enforce MFA for all administrative accounts as a compensating control.

Mapped D3FEND Techniques:

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CVE-2026-26035FortinetFortiWebAuthentication BypassVulnerabilityWAF

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.