Header injection in captive portal authentication form

Low RiskCVSS 3.1FG-IR-26-153Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A header injection vulnerability exists in the captive portal authentication form in FortiOS and FortiProxy. By injecting malicious HTTP headers, an attacker can manipulate the captive portal response to redirect users to phishing sites or inject malicious content. The vulnerability affects FortiOS versions 7.6.0–7.6.4, 7.4 (all versions), and 7.2 (all versions), as well as FortiProxy versions 7.6.0–7.6.4, 7.4 (all versions), and 7.2 (all versions).

What this means
What could happen
An attacker could inject malicious HTTP headers into the captive portal login page, potentially redirecting users to a phishing site or injecting content that tricks them into revealing credentials. This affects any organization using FortiOS or FortiProxy as a gateway where users authenticate through the captive portal.
Who's at risk
Network administrators at utilities and water authorities using Fortinet FortiOS or FortiProxy as perimeter security gateways with captive portal authentication enabled. This includes any organization using these appliances to control guest network access or enforce pre-authentication policies.
How it could be exploited
An attacker crafts a specially malicious request targeting the captive portal form and relies on the form's failure to properly validate HTTP headers. If a user clicks a link or visits a URL controlled by the attacker, the injected headers can modify the captive portal response, redirecting the user to a fake login page or injecting JavaScript to steal credentials.
Prerequisites
  • Network access to the captive portal (typically reachable from the Internet)
  • User interaction required (user must click a malicious link or visit a crafted URL)
  • Captive portal authentication enabled on the FortiOS or FortiProxy appliance
remotely exploitablelow complexityuser interaction requiredlow CVSS score (3.1)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
FortiOS7.6.0 - 7.6.47.6.5+
FortiOS7.4 all versionsMigrate to fixed release
FortiOS7.2 all versionsMigrate to fixed release
FortiProxy7.6.0 - 7.6.47.6.5+
FortiProxy7.4 all versionsMigrate to fixed release
FortiProxy7.2 all versionsMigrate to fixed release
Remediation & Mitigation
0/5
Do now
0/1
WORKAROUNDDisable captive portal if not required for operations, or restrict access to captive portal to internal networks only
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS 7.6 to version 7.6.5 or later
HOTFIXMigrate FortiOS 7.4 and 7.2 to the latest supported release (7.6.5 or later)
FortiProxy
HOTFIXUpdate FortiProxy 7.6 to version 7.6.5 or later
HOTFIXMigrate FortiProxy 7.4 and 7.2 to the latest supported release (7.6.5 or later)
API: /api/v1/advisories/beb0984d-6f8a-4cd4-8022-077c9f09f0d5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Header injection in captive portal authentication form | CVSS 3.1 - OTPulse