AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-70466

MEDIUM · CVSS 5.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Fortinet FortiWeb versions 8.0.0 to 8.0.2, 7.6.0 to 7.6.5, and all versions of 7.4, 7.2, and 7.0 are vulnerable due to an incomplete list of disallowed inputs, which could enable attackers to bypass access controls. This vulnerability poses a medium risk, potentially allowing unauthorized access to sensitive data or functionalities. Organizations using affected FortiWeb products should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-70466
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%
Fortinet

Original NVD Description

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>