VDB

GCVE-110-NCSC-2026-300

GCVE-110-NCSC-2026-300
Advisory PublishedCVSS 5.3/10
Vulnetix · Advisory published August 13, 2026
Multiple versions of Fortinet FortiWeb contain an Improper Authentication vulnerability that allows remote unauthenticated attackers to access the FortiWeb GUI/CLI using random credentials, including when Remote Radius Type Admin Authentication is configured with specific non-default settings.

Weaknesses (CWE)

CWE-184Incomplete List of Disallowed Inputs

Risk Scores

CVSS 3.1
5.3/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Fortinetvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

390 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›