CVE-2026-24640

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

12 Mar 2026, 20:12

Type Values Removed Values Added
CWE CWE-787
Summary
  • (es) Una vulnerabilidad de desbordamiento de búfer basado en pila [CWE-121] en Fortinet FortiWeb 8.0.0 a 8.0.2, FortiWeb 7.6.0 a 7.6.6, FortiWeb 7.4 todas las versiones, FortiWeb 7.2 todas las versiones, FortiWeb 7.0.2 a 7.0.12 puede permitir a un atacante remoto autenticado que pueda eludir la protección de pila y ASLR ejecutar código o comandos arbitrarios a través de solicitudes HTTP manipuladas.
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-087 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-087 - Vendor Advisory
First Time Fortinet
Fortinet fortiweb
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

10 Mar 2026, 18:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:18

Updated : 2026-03-12 20:12


NVD link : CVE-2026-24640

Mitre link : CVE-2026-24640

CVE.ORG link : CVE-2026-24640


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write