Description
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
Published: 2026-03-10
Score: 2.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via HTTP daemon crash
Action: Patch
AI Analysis

Impact

A NULL pointer dereference flaw in Fortinet FortiWeb allows an authenticated attacker to send specially crafted HTTP requests that cause the HTTP service to crash. The attack does not grant code execution or privilege escalation; instead, it results in a denial of service where the web interface becomes unavailable until the service or appliance is restarted.

Affected Systems

Affected products include FortiWeb from version 7.0 through 8.0. The vulnerability impacts FortiWeb 8.0.0‑8.0.2, 7.6.0‑7.6.6, all 7.4 releases, all 7.2 releases, and all 7.0 releases.

Risk and Exploitability

With a CVSS score of 2.5, the flaw is considered low severity. The EPSS score of less than 1% indicates a very low probability that the vulnerability will be actively exploited in the wild, and it is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the FortiWeb appliance, after which they can send malformed HTTP requests from the network. The available remediation is an official patch; no known workarounds exist.

Generated by OpenCVE AI on April 16, 2026 at 03:49 UTC.

Remediation

Vendor Solution

Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above


OpenCVE Recommended Actions

  • Apply the official FortiWeb update to version 8.0.3 or later, or to 7.6.7 or later, depending on your current release. This patch removes the NULL pointer dereference issue that allows the HTTP daemon to crash.
  • Reboot the FortiWeb appliance after the upgrade to ensure the new firmware and configuration changes take effect.
  • Implement network access controls to restrict unauthenticated HTTP traffic to trusted sources and monitor HTTP service logs for crash events until the patch has been deployed across all appliances.

Generated by OpenCVE AI on April 16, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference Crash in FortiWeb HTTP Daemon

Thu, 12 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Description A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
First Time appeared Fortinet
Fortinet fortiweb
Weaknesses CWE-476
CPEs cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:8.0.2:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiweb
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortiweb
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-03-12T14:27:39.136Z

Reserved: 2026-01-23T15:09:07.476Z

Link: CVE-2026-24641

cve-icon Vulnrichment

Updated: 2026-03-12T14:27:34.630Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T18:18:28.687

Modified: 2026-03-12T20:10:46.500

Link: CVE-2026-24641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T04:00:09Z

Weaknesses