Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Published 29 Jul 2026Updated 29 Jul 202617 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Affected versions

FortiWeb: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52495Fortinet FortiWeb v8.0.1 - Auth Bypassnu11secur1ty2026-04-06VerifiedExploit-DB 52502FortiWeb 8.0.2 - Remote Code ExecutionMohammed Idrees Banyamer2026-04-08VerifiedPoC-in-GitHub · fevar54/CVE-2025-64446-PoC---FortiWeb-Path-TraversalPoC de CVE-2025-64446: path traversal a RCE en Fortinet FortiWeb. Solo uso educativo.★ 7fevar542025-11-14CandidatePoC-in-GitHub · sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC★ 13sxyrxyy2025-11-14CandidatePoC-in-GitHub · soltanali0/CVE-2025-64446-Exploit★ 14soltanali02025-11-15CandidatePoC-in-GitHub · sensepost/CVE-2025-64446A scanner for the FortiNet vulnerability CVE-2025-64446★ 32sensepost2025-11-17CandidatePoC-in-GitHub · D3crypT0r/CVE-2025-64446FortiWeb Unauthenticated RCE via Path Traversal & CGI Auth Bypass★ 0D3crypT0r2025-11-17CandidatePoC-in-GitHub · verylazytech/CVE-2025-64446CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.★ 3verylazytech2025-11-17CandidatePoC-in-GitHub · Death112233/CVE-2025-64446-★ 0Death1122332025-11-19CandidatePoC-in-GitHub · AN5I/cve-2025-64446-fortiweb-exploitSecurity research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)★ 1AN5I2025-11-21CandidatePoC-in-GitHub · lequoca/fortinet-fortiweb-cve-2025-64446-58034Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)★ 0lequoca2025-12-21CandidatePoC-in-GitHub · eagle-nett/FORTIWEB_CVE-2025-64446-58034Lỗ hổng CVE-2025-64446 & CVE-2025-58034★ 0eagle-nett2026-03-22CandidatePoC-in-GitHub · 0xBlackash/CVE-2025-64446CVE-2025-64446★ 00xBlackash2026-03-26CandidatePoC-in-GitHub · litndat/Vulnerability-CVE-2025-64446-CVE-2025-58034Lỗ hổng FORTIWEB_CVE-2025-64446 & CVE-2025-58034★ 0litndat2026-06-24CandidatePoC-in-GitHub · CerberusMrXi/FortiWeb-cve-2025-64446-RCE-exploitSecurity research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.★ 2CerberusMrXi2026-07-30Candidate