← Back

CVE-2026-40688

nvd nist
Published: Apr 14, 2026Modified: Jul 24, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Affected (3)

Products: Fortinet: Fortiweb
1 product
Fortiweb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.4.0 to 7.4.12
From 7.6.0 to 7.6.7
From 8.0.0 to 8.0.4

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.