Fortinet FortiWeb Vulnerability Allows Unauthenticated Admin Access via RADIUS
A critical Improper Authentication vulnerability in FortiWeb's Remote Radius Type Admin Authentication can allow unauthenticated attackers to log in with arbitrary credentials.

Fortinet has disclosed a critical Improper Authentication vulnerability (CVSS 8.8) affecting its FortiWeb Web Application Firewall. The flaw, identified as CWE-287, resides within the Remote Radius Type Admin Authentication feature when configured with specific, non-default settings.
Exploitation of this vulnerability allows an unauthenticated remote attacker to bypass authentication mechanisms and gain access to the FortiWeb GUI and CLI. Crucially, the attacker can log in using arbitrary usernames and passwords, effectively granting them unauthorized administrative control over the affected appliance. This broken access control presents a significant risk to organizations relying on FortiWeb for their web application security.
The vulnerability impacts several versions of FortiWeb, including versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, and 7.2.0 through 7.2.13. Fortinet strongly advises users to upgrade to the latest available versions to remediate the issue.
Specifically, users should upgrade to FortiWeb 8.0.3 or later, 7.6.7 or later, 7.4.12 or later, or 7.2.13 or later. These updates contain the necessary patches to address the improper authentication flaw.
For organizations unable to immediately upgrade, Fortinet has provided a workaround. If the 'Wildcard' option is enabled for administrators, disabling this setting can mitigate the vulnerability. This can be done through the GUI by navigating to System > Administrators, editing the relevant Remote Type administrator account, and disabling the Wildcard option. Alternatively, the CLI command config system admin, edit <Remote type administrator account>, set wildcard disable, and extend can be used.
This vulnerability was discovered internally by Fortinet as part of a routine audit, highlighting the importance of continuous security assessments. The timeline indicates initial publication on August 12, 2026, with no mention of active exploitation in the wild at the time of disclosure.
This finding underscores the persistent threat posed by misconfigurations in authentication and access control systems. Organizations must ensure that security features like RADIUS integration are not only configured correctly but also regularly audited to prevent such critical vulnerabilities from being exploited.