FortiWeb WAF Bypass Vulnerability Allows Policy Evasion
Fortinet has disclosed a vulnerability in its FortiWeb Web Application Firewall that allows unauthenticated attackers to bypass security policies through crafted HTTP requests.

Fortinet has issued a security advisory detailing a vulnerability within its FortiWeb Web Application Firewall (WAF) that could permit unauthenticated attackers to bypass security policies. The flaw, identified under CWE-184 (Incomplete List of Disallowed Inputs), carries a CVSSv3 score of 4.8, indicating a moderate severity level. This vulnerability allows attackers to craft specific HTTP requests that circumvent the WAF's intended security controls.
The bypass mechanism relies on an incomplete list of disallowed inputs within the WAF's processing logic. By manipulating the Content-Encoding header or other request components, attackers can potentially inject malicious payloads or access restricted resources that the WAF should have blocked. This could lead to various security breaches, including cross-site scripting (XSS) attacks, SQL injection, or unauthorized access to sensitive application functions.
Fortinet has provided specific version information for affected FortiWeb deployments. Versions 8.0.0 through 8.0.2 require an upgrade to 8.0.3 or later. For version 7.6, releases 7.6.0 through 7.6.5 need to be upgraded to 7.6.6 or above. FortiWeb versions 7.4 and 7.2 are affected in all their respective versions and require migration to a fixed release, implying that direct patching might not be available for these older lines.
To address the vulnerability, Fortinet has released a virtual patch named "FG-VD-10009598.0day." This virtual patch is available through FortiWeb Management Web Portal (FMWP) database update 26.071, offering an immediate mitigation option for customers who cannot immediately upgrade their WAF software. This allows organizations to bolster their defenses while planning for a full version upgrade.
The vulnerability was responsibly disclosed to Fortinet by Rui Xi, affiliated with the Beijing University of Posts and Telecommunications. The timeline indicates that the initial publication date was August 12, 2026, aligning with the release of the advisory and the availability of the virtual patch. This disclosure follows standard responsible disclosure practices, allowing vendors time to develop and distribute fixes.
This WAF bypass vulnerability underscores the ongoing challenges in securing web applications. Attackers continuously probe for weaknesses in security devices like WAFs, which are critical layers of defense. The ability to bypass these controls can significantly weaken an organization's overall security posture, making it imperative for administrators to keep their WAFs updated and apply available patches or virtual patches promptly.
Organizations utilizing FortiWeb WAF are strongly advised to consult the Fortinet PSIRT advisory for detailed remediation steps. Prompt application of the recommended upgrades or the virtual patch is crucial to prevent potential exploitation and maintain the integrity of web application security defenses. The vulnerability highlights the need for continuous monitoring and updating of security infrastructure to counter evolving threats.