CVE-2024-23665: Fortinet FortiWeb

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

Affected products

  • Fortinet FortiWeb: from 6.3.0, up to and including 6.3.23; from 6.4.0, up to and including 6.4.3; from 7.0.0, up to and including 7.0.10; from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2024-06-03. Last modified 2026-06-17.