CVE-2026-70466: Fortinet FortiWeb
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
Affected products
- Fortinet FortiWeb: from 7.0.0, before 7.6.6 (fixed in 7.6.6); from 8.0.0, before 8.0.3 (fixed in 8.0.3)
Published 2026-08-12. Last modified 2026-09-08.