SB2026081395 - Incomplete List of Disallowed Inputs in FortiWeb



SB2026081395 - Incomplete List of Disallowed Inputs in FortiWeb

Published: August 13, 2026

Security Bulletin ID SB2026081395
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-70466)

CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to incomplete list of disallowed inputs. An unauthenticated attacker can bypass policies via specifically crafted requests.


Remediation

Install update from vendor's website.