---
id: CVE-2026-70466
title: >-
  A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb
  8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions,
  FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to
  improper a…
summary: >-
  A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb
  8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions,
  FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to
  improper a…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-184
vendor: fortinet
product: fortiweb
affected:
  - 'fortiweb >= 7.0.0, < 7.6.6'
  - 'fortiweb >= 8.0.0, < 8.0.3'
patched:
  - fortiweb 8.0.3
published: '2026-08-12'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:02:08.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70466'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-157'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
epss: 0.0031
epssPercentile: 0.21219
ingestedAt: '2026-09-08T21:11:12.275Z'
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-12T00:00:00+00:00'
scores:
  nvd: 5.3
  cna: 4.8
---

## Overview

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

## Affected

- `fortiweb >= 7.0.0, < 7.6.6`
- `fortiweb >= 8.0.0, < 8.0.3`

## Remediation

Upgrade past the affected range:

- `fortiweb 8.0.3`
