CVE-2026-30897: Buffer Overflow
A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30897?
CVE-2026-30897 is classified as a critical severity vulnerability due to the potential for remote code execution.
What versions of Fortinet FortiWeb are affected by CVE-2026-30897?
CVE-2026-30897 affects Fortinet FortiWeb versions 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, 7.4.0 through 7.4.11, as well as all versions of 7.2 and 7.0.
How do I fix CVE-2026-30897?
To fix CVE-2026-30897, you should upgrade your FortiWeb installation to the latest version that is not affected by this vulnerability.
What type of vulnerability is CVE-2026-30897?
CVE-2026-30897 is a stack-based buffer overflow vulnerability.
Can CVE-2026-30897 be exploited remotely?
Yes, CVE-2026-30897 can be exploited by a remote authenticated attacker who can bypass stack protection and ASLR.