
What is CVE-2026-26035?
CVE-2026-26035 is an improper authentication vulnerability (CWE-287) in Fortinet FortiWeb, disclosed by Fortinet on August 12, 2026 in advisory FG-IR-26-158 under the title “Broken access control in the RADIUS type admin group.” The flaw sits in FortiWeb’s remote RADIUS administrator authentication path, where the appliance fails to correctly validate an administrative login before granting access.
There is a discrepancy in how the issue has been scored. Fortinet rates it High severity in its own advisory. Third-party vulnerability trackers report a CVSS v3.1 base score of 9.8 (Critical). The most likely explanation for the gap is that the vendor rating accounts for the configuration precondition and the generic score does not. Defenders sizing this issue should treat the configuration state of their own appliances as the deciding factor rather than the headline number.
Exploitation is described as pre-authentication. Public reporting states that a remote attacker with no valid credentials can log in to the FortiWeb GUI and CLI using arbitrary usernames and passwords, obtaining administrative access to the appliance. Fortinet records the issue as internally discovered, with the CLI listed as the affected component and the attack type as unauthenticated.
Successful exploitation puts the attacker in the administrative context of a web application firewall. That position allows policy changes, certificate and key access, log manipulation, and visibility into the traffic the appliance inspects. No public proof of concept has been reported at the time of writing, and Fortinet has not reported exploitation in the wild.
What assets are affected by CVE-2026-26035?
Fortinet lists the 8.0, 7.6, 7.4, 7.2, and 7.0 branches of FortiWeb as affected. Third-party trackers report the specific ranges as 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12, and 7.0.0 through 7.0.12.
The exposure is narrower than the version list suggests. Because the flaw sits in the remote RADIUS administrator authentication path, the deployments at risk are those configured to authenticate administrators against a RADIUS server through an admin group, rather than every FortiWeb instance running an affected build. Organizations that use only local administrator accounts are in a materially different position from those that centralize appliance administration through RADIUS.
In practice, an affected asset is a web application firewall sitting at the network edge in front of production web applications and APIs. FortiWeb appliances are deployed as hardware, as virtual machines, and in cloud environments, and their management interfaces are frequently reachable from outside the corporate network to support remote administration, managed service providers, or distributed operations teams. RADIUS-backed admin authentication is common in exactly those environments, because it is the mechanism that lets a central identity source govern who can administer appliances spread across sites and regions.
What does our data show about exposure patterns?

Across the assets CyCognito observed running FortiWeb, exposure among classified organizations is led by Financials at 18.2% of the set, with Communication Services contributing 12.7% and Energy 7.3%. The Others bucket at 61.8% is dominated by organizations for which no industry classification was available in the source data, so the named sector shares describe the classified portion of the set rather than the full population.
The concentration in Financials is consistent with how the sector operates. Banks and diversified financial institutions run large numbers of internet-facing web applications and APIs across retail, corporate, and partner channels, and they front them with web application firewalls as a matter of policy and regulatory expectation. The same institutions typically administer those appliances through centralized identity infrastructure, which is what makes RADIUS-backed admin groups a normal deployment pattern rather than an exception. Communication Services shows a similar profile for different reasons, with media and entertainment groups operating many distinct brands and properties, each with its own edge infrastructure and its own operational history.
The broader pattern is that security appliances inherit the visibility problems of the assets they protect. A web application firewall is deployed to reduce risk at the edge, which means it is placed at the edge by design, with a management plane that has to be reachable by whoever administers it. When the identity path into that management plane is the vulnerable component, the appliance’s protective role becomes a liability rather than a mitigation. Organizations that can enumerate their web applications but not the appliances in front of them, or that know the appliances exist but not how administrator authentication is configured on each one, cannot answer whether this issue applies to them.
Note on confidence: this dataset identifies assets observed running FortiWeb based on service fingerprinting. It does not confirm the running version or the administrator authentication configuration, so the assets described here are potentially affected rather than confirmed vulnerable.
Are fixes available?
Fortinet has published an advisory for this issue as FG-IR-26-158. The specific fixed build numbers could not be independently confirmed at the time of writing, and at least one public tracker noted that patch details were not available in the initial advisory.
The affected ranges reported by third-party trackers stop below builds that are already generally available on several branches, which suggests the 8.0, 7.6, and 7.4 branches have shipping releases beyond the vulnerable range. The 7.2 and 7.0 branches are reported as affected through their most recent published builds, which leaves their fix status less clear.
Given that ambiguity, defenders should confirm the fixed version for their branch directly with Fortinet through the advisory and the vendor upgrade path tool rather than inferring a safe build from the affected range. Until that confirmation is in hand, appliances on any affected branch should be treated as unpatched.
Are there any other recommended actions to take?
Until patching is confirmed, defenders should:
- Inventory all FortiWeb appliances and identify those using remote RADIUS admin authentication
- Restrict management interface access to a dedicated administration network
- Disable RADIUS-based admin groups where local administrator accounts are sufficient
- Audit FortiWeb administrator accounts and recent configuration changes for unauthorized activity
- Monitor FortiWeb admin login events for successful logins from unexpected source addresses
How can CyCognito help your organization?
CyCognito published an Emerging Threat Advisory for CVE-2026-26035 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.
To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.