---
id: CVE-2024-23668
title: >-
  An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager
  7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through
  6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or
  commands …
summary: >-
  An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager
  7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through
  6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or
  commands …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: fortinet
product: fortiwebmanager
affected:
  - 'fortiwebmanager >= 6.2.3, < 6.2.5'
  - 'fortiwebmanager >= 7.0.0, < 7.0.5'
  - fortiwebmanager = 6.0.2
  - fortiwebmanager = 6.3.0
  - fortiwebmanager = 7.2.0
patched:
  - fortiwebmanager 7.0.5
published: '2024-06-03'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23668'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-222'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-222'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00657
epssPercentile: 0.49308
ingestedAt: '2026-07-08T14:51:15.589Z'
---

## Overview

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

## Affected

- `fortiwebmanager >= 6.2.3, < 6.2.5`
- `fortiwebmanager >= 7.0.0, < 7.0.5`
- `fortiwebmanager = 6.0.2`
- `fortiwebmanager = 6.3.0`
- `fortiwebmanager = 7.2.0`

## Remediation

Upgrade past the affected range:

- `fortiwebmanager 7.0.5`
