CVE-2026-24017
8.1Fortinet · FortiWeb
A rate-limiting bypass vulnerability in Fortinet FortiWeb allows remote unauthenticated attackers to circumvent authentication frequency controls via crafted requests.
Executive summary
A high-severity authentication bypass vulnerability in Fortinet FortiWeb allows unauthenticated remote attackers to circumvent rate-limiting protections, potentially facilitating brute-force credential attacks.
Vulnerability
This flaw is an improper control of interaction frequency (CWE-799) that permits a remote unauthenticated attacker to bypass authentication rate-limits. By sending crafted requests, an attacker may attempt to overcome standard lockout or throttling mechanisms.
Business impact
The ability to bypass rate-limiting controls significantly increases the risk of successful credential stuffing or brute-force attacks against administrative or user accounts. Given the CVSS score of 8.1, this represents a high risk to organizational security, as it undermines the primary defense mechanism against unauthorized access. Successful exploitation could lead to full account compromise, resulting in data breaches, unauthorized configuration changes, or severe operational disruption.
Remediation
Immediate Action: Upgrade to FortiWeb version 8.0.3, 7.6.6, 7.4.11, 7.2.12, 7.0.12, or the latest available patched version provided by the vendor.
Proactive Monitoring: Review authentication logs for anomalous spikes in login attempts or patterns suggesting an attempt to bypass rate-limiting thresholds.
Compensating Controls: Ensure that additional layers, such as account lockout policies, multi-factor authentication, and IP-based reputation filtering, are enforced to mitigate the impact of potential brute-force attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high severity of this vulnerability, administrators should prioritize the application of the vendor-provided patches. Updating the firmware is the only definitive way to restore functional rate-limiting controls and prevent potential automated exploitation against your FortiWeb infrastructure.