Decoding the world of cybersecurity

Fortinet patches two authentication weaknesses

Fortinet has fixed separate authentication weaknesses in FortiWeb and FortiManager, including a configuration-dependent FortiWeb administrator bypass and a FortiManager device-impersonation flaw.

Fortinet patches two authentication weaknesses
Summary
  • CVE-2026-26035 can permit unauthenticated FortiWeb GUI or CLI access where specific Remote RADIUS administrator settings are used.
  • CVE-2026-70468 affects FortiManager and can permit impersonation of a managed FortiGate under defined certificate and configuration conditions.
  • Fortinet has not disclosed known exploitation of the two August flaws.

Fortinet has patched separate authentication weaknesses in FortiWeb and FortiManager, affecting two security platforms that sit close to internet-facing applications and centralised network administration.

The more severe FortiWeb issue, CVE-2026-26035, is an improper-authentication vulnerability affecting multiple supported branches. Under particular Remote RADIUS administrator configurations, a remote unauthenticated attacker may be able to log in to the FortiWeb graphical or command-line interface using an arbitrary username and password.

The configuration dependency materially limits the affected population. The vulnerability is not evidence that every FortiWeb appliance can be accessed with random credentials, so exposure assessments need to account for both software version and administrator-authentication settings.

Fortinet published the issue under advisory FG-IR-26-158 on 12 August. The flaw affects FortiWeb versions across the 8.0, 7.6, 7.4, 7.2 and 7.0 families, with updated releases available for supported branches.

FortiManager is affected by a separate flaw, CVE-2026-70468. The vulnerability concerns authentication in the FortiGate-to-FortiManager management relationship and may permit a remote unauthenticated attacker to impersonate a managed FortiGate when a specific CLI option is enabled and the attacker also possesses a valid certificate.

Those prerequisites make the FortiManager weakness different from the FortiWeb administrator-login bypass. Both concern authentication, but they affect distinct trust relationships and should not be treated as one universal access-control failure across Fortinet products.

No known exploitation has been disclosed for either August issue. That gives organisations an opportunity to remediate before the vulnerabilities become incident-response problems, although Fortinet appliances have historically attracted rapid attacker attention when consequential flaws become public.

FortiWeb commonly sits close to public applications and is expected to enforce security policy against untrusted traffic. Administrative access to that layer can expose configuration and change the controls applied to the applications behind it, increasing the significance of an authentication weakness beyond the appliance itself.

FortiManager carries a different form of concentration risk. It centralises administration across groups of FortiGate devices, which means device identity and the trust established through the FGFM management protocol have security consequences across a wider network estate.

Machine identity is therefore central to the FortiManager issue. Network devices often authenticate one another using certificates and protocol-specific trust relationships that receive less routine attention than human administrator accounts, even though successful device impersonation can cross an important management boundary.

The flaws also reinforce the need to include security appliances in ordinary asset and configuration governance. Network infrastructure can remain deployed for long periods, while authentication settings vary by site, administrator or managed-service arrangement. Knowing that a product family is affected is not sufficient to establish whether a particular installation meets the exploit prerequisites.

European resilience and regulatory regimes increase scrutiny of the same management layer. Where network-security products support important or regulated services, organisations need evidence that vulnerable versions and exposed configurations can be identified quickly rather than relying on appliance inventories that are incomplete or owned entirely by a supplier.

Fortinet has published fixed versions and advisory detail for both flaws. The immediate task is configuration-aware remediation: determine which FortiWeb installations use the affected RADIUS model, which FortiManager systems meet the relevant FGFM conditions, and apply the appropriate updates without inflating either issue into a broader compromise claim.

×