Fortinet FortiWeb Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Fortinet FortiWeb versions 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, as well as all versions of FortiWeb 7.2 and 7.0. This vulnerability may allow a remote authenticated attacker who can bypass stack protection and Address Space Layout Randomization (ASLR) to execute arbitrary code or commands by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code or commands on the affected system.

Remediation

Users of Fortinet FortiWeb should upgrade to FortiWeb 8.0.4 or above, FortiWeb 7.6.7 or above, FortiWeb 7.4.12 or above. Users on FortiWeb 7.2 or 7.0 should migrate to a fixed release.

Added: Mar 10, 2026, 6:57 PM
Updated: Mar 10, 2026, 6:57 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
7.5
exploitability
4.8
remediation
7.7
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.