CVE-2026-70466
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
- EPSS probability
- 0.29%
- CWE
- CWE-184
- Published
- 2026-08-12
- Last modified
- 2026-09-15
Affected products
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2024-5217 — Incomplete Input Validation in GlideExpression Script
- CVE-2026-49869 — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
- CVE-2026-33396 — OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
- CVE-2026-28363 — In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation
- CVE-2026-28783 — Craft has a Twig Function Blocklist Bypass
- CVE-2023-45133 — Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
- CVE-2026-32940 — SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
- CVE-2025-58361 — Promptcraft Forge Studio's incomplete URL check is vulnerable to XSS via SVG