CVE-2026-39814

EUVD-2026-22346
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
fortinetfortiweb
7.0.10 ≤
𝑥
≤ 7.0.12
fortinetfortiweb
7.2.0 ≤
𝑥
≤ 7.2.12
fortinetfortiweb
7.4.1 ≤
𝑥
≤ 7.4.12
fortinetfortiweb
7.6.0 ≤
𝑥
< 7.6.7
fortinetfortiweb
8.0.0 ≤
𝑥
< 8.0.3
𝑥
= Vulnerable software versions