Broken access control in the RADIUS type admin group
FG-IR-26-158
CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.