CVE-2026-24017
HIGH EPSS 50.8%
Published Mar 10, 20263mo ago · Modified Jun 17, 20261w ago
8.1 CVSS 3.1
Published Mar 10, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends on the attacker's resources and the password target complexity.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
50.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-799
Affected Products 5
References 1
- fortiguard.fortinet.com https://fortiguard.fortinet.com/psirt/FG-IR-26-082
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.