Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-44277: Fortinet FortiAuthenticator: Unauthorized Code Execution

CVE-2026-44277
Summary

Fortinet's FortiAuthenticator software has a security issue that could allow an attacker to run unauthorized code or commands on the system. This could potentially allow the attacker to access or modify sensitive data. Fortinet recommends updating to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
fortinet fortiauthenticator >= 6.4.0, <= 6.4.10
>= 6.5.0, < 6.5.7
>= 6.6.0, < 6.6.9
>= 8.0.0, < 8.0.3
cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*
Original title
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow atta...
Original description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
nvd CVSS3.1 9.8
Vulnerability type
CWE-284 Improper Access Control
Published: 12 May 2026 · Updated: 28 May 2026 · First seen: 15 May 2026