What is CVE-2026-26035?
This vulnerability is an improper authentication flaw in Fortinet FortiWeb that could allow a remote unauthenticated attacker to log into the device. Affected versions include multiple branches such as 8.0, 7.6, 7.4, 7.2, and 7.0. It is strongly recommended to apply the patches provided by Fortinet immediately.
Azərbaycanca: Bu zəiflik Fortinet FortiWeb cihazlarında autentifikasiya mexanizmindəki nöqsan səbəbindən uzaqdan təcavüzkarın heç bir etimadnamə olmadan sistemə daxil olmasına imkan verir. Təsirə məruz qalan versiyalar arasında 8.0, 7.6, 7.4, 7.2, 7.0 branch-ləri mövcuddur. Dərhal Fortinet-in təqdim etdiyi yamaqları tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Fortinet
FAQ2
Which product is affected by CVE-2026-26035?
This vulnerability affects Fortinet FortiWeb devices.
What is the main threat of CVE-2026-26035?
A remote attacker can log into the device without any credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.