VYPR
advisoryPublished Aug 12, 2026· 1 source

FortiOS Vulnerability Allows Unauthenticated DoS Attacks on Web Interface

FortiOS is susceptible to a CWE-770 vulnerability enabling unauthenticated attackers to launch slow HTTP denial-of-service attacks against its web interface.

Fortinet has disclosed a significant vulnerability, identified as CWE-770 (Allocation of Resources Without Limits or Throttling), affecting its FortiOS operating system. This flaw allows unauthenticated attackers to conduct slow HTTP denial-of-service (DoS) attacks targeting the device's web interface. The vulnerability arises from an insufficient mechanism for limiting or throttling resource allocation when processing HTTP requests.

Attackers can exploit this weakness by sending specially crafted HTTP requests to the web interface. The lack of proper resource management means these requests can consume excessive server resources, such as CPU or memory, leading to a disruption of service availability. This can render the web interface unresponsive to legitimate users, including administrators attempting to manage the device.

The affected versions of FortiOS include 7.6.0 through 7.6.6, and all versions of FortiOS 7.4. FortiOS 8.0 is not affected by this specific vulnerability. Fortinet recommends upgrading to FortiOS 7.6.7 or later for affected 7.6 releases. For users on FortiOS 7.4, a migration to a fixed release is advised, following Fortinet's upgrade path tool.

To further mitigate the risk, Fortinet has provided configuration commands for versions 7.6.7 and 8.0.0. Administrators can set timeout thresholds for receiving complete HTTP headers and bodies using commands like set admin-http-request-header-timeout and set admin-http-request-body-timeout. Additionally, a workaround suggests restricting administrator logins to trusted hosts only and disabling GUI access on internet-facing interfaces to limit the attack surface.

This vulnerability represents a regression from a previously addressed issue, FG-IR-19-013, highlighting the ongoing challenges in securing web interfaces against resource exhaustion attacks. The CVSSv3 score for this vulnerability is 5.0, indicating a moderate severity level.

Fortinet has acknowledged Iván Domínguez from Zerolynx for responsibly disclosing this vulnerability. The initial publication date for this advisory was August 12, 2026.

Organizations utilizing FortiOS should prioritize applying the recommended updates and implementing the suggested workarounds to protect their network devices from potential DoS attacks. The ability for unauthenticated attackers to disrupt services underscores the importance of robust input validation and resource management in network device firmware.

Synthesized by Vypr AI