CVE-2024-46671: Fortinet FortiWeb

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.

Affected products

  • Fortinet FortiWeb: from 7.0.0, before 7.2.11 (fixed in 7.2.11); from 7.4.0, before 7.4.7 (fixed in 7.4.7); from 7.6.0, before 7.6.3 (fixed in 7.6.3)

Published 2025-04-08. Last modified 2026-06-17.