CVE-2017-14189: Fortinet FortiWeb Manager

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.

Affected products

  • Fortinet FortiWeb Manager: version 5.8.0 only

Published 2017-11-29. Last modified 2026-06-17.