SB2026081395 - Incomplete List of Disallowed Inputs in FortiWeb
Published: August 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-70466)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to incomplete list of disallowed inputs. An unauthenticated attacker can bypass policies via specifically crafted requests.
Remediation
Install update from vendor's website.