CVE-2026-44277
Modified
Modified - Updated After Analysis
BaseFortify
Publication date: 2026-05-12
Last updated on: 2026-05-28
Assigner: Fortinet, Inc.
Description
Description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortiauthenticator | From 6.4.0 (inc) to 6.4.10 (inc) |
| fortinet | fortiauthenticator | From 6.5.0 (inc) to 6.5.7 (exc) |
| fortinet | fortiauthenticator | From 6.6.0 (inc) to 6.6.9 (exc) |
| fortinet | fortiauthenticator | From 8.0.0 (inc) to 8.0.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |