CVE-2023-22636: Fortinet FortiWeb

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.

Affected products

  • Fortinet FortiWeb: from 6.3.6, up to and including 6.3.21; from 6.4.0, up to and including 6.4.2; from 7.0.0, up to and including 7.0.4

Published 2023-02-27. Last modified 2026-06-17.