← Retour aux CVEs
CVE-2026-24641
LOW2.7
Description
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.
Details CVE
Score CVSS v3.12.7
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie3/10/2026
Derniere modification3/12/2026
Sourcenvd
Observations honeypot0
Produits affectes
fortinet:fortiweb
Faiblesses (CWE)
CWE-476
References
https://fortiguard.fortinet.com/psirt/FG-IR-26-089(psirt@fortinet.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.