CVE-2017-14191: Fortinet FortiWeb

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.

Affected products

  • Fortinet FortiWeb: from 5.6.0, before 6.1.0 (fixed in 6.1.0)

Published 2018-03-20. Last modified 2026-06-17.