Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager.
In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings.
A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains.
The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account.
“When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains.
CVE-2026-26035 was patched in FortiWeb versions 8.0.3,...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE