Description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
Published: 2026-05-12
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control vulnerability in Fortinet FortiAuthenticator appliances affects versions 8.0.2, 8.0.0, 6.6.0 through 6.6.8, and 6.5.0 through 6.5.6. By sending crafted requests, an attacker can execute unauthorized code or commands. This flaw allows remote code execution with the privileges of the management service, compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑284.

Affected Systems

Systems running FortiAuthenticator 8.0.0, 8.0.2, 6.6.0‑6.6.8, 6.5.0‑6.5.6, as well as earlier 6.4.x and earlier minor releases, are impacted. The vendor recommends upgrading to FortiAuthenticator 8.0.3 or higher, or to version 6.6.9, 6.5.7, 6.4.11, or 6.3.5, depending on the product line.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, while the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker requires network access to the FortiAuthenticator appliance and can exploit unauthenticated or low‑privileged API calls or web interface endpoints. Successful exploitation would grant the attacker full control of the appliance, enabling lateral movement or compromise of connected devices.

Generated by OpenCVE AI on May 28, 2026 at 13:25 UTC.

Remediation

Vendor Solution

Upgrade to FortiAuthenticator version 8.0.3 or above Upgrade to FortiAuthenticator version 8.0.1 or above Upgrade to FortiAuthenticator version 6.6.9 or above Upgrade to FortiAuthenticator version 6.5.7 or above Upgrade to FortiAuthenticator version 6.4.11 or above Upgrade to FortiAuthenticator version 6.3.5 or above


OpenCVE Recommended Actions

  • Upgrade FortiAuthenticator to version 8.0.3 or later. This patch resolves the access control flaw and prevents code execution.
  • If running the 6.6.x line, move to version 6.6.9 or later. This update contains the necessary fixes for the vulnerability.
  • For the 6.5.x line, upgrade to version 6.5.7 or newer, which addresses the issue.
  • If an immediate upgrade is not possible, block external traffic to the FortiAuthenticator management interfaces with firewall rules, limiting exposure to the vulnerable component.

Generated by OpenCVE AI on May 28, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 13:45:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in FortiAuthenticator Enabling Remote Code Execution

Thu, 28 May 2026 10:15:00 +0000

Type Values Removed Values Added
Description A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here> A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.

Fri, 15 May 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:*

Tue, 12 May 2026 20:30:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in FortiAuthenticator Enabling Remote Code Execution

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortiauthenticator
Weaknesses CWE-284
CPEs cpe:2.3:a:fortinet:fortiauthenticator:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:8.0.2:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiauthenticator
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'}


Subscriptions

Fortinet Fortiauthenticator
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-05-28T09:30:16.137Z

Reserved: 2026-05-05T17:24:16.702Z

Link: CVE-2026-44277

cve-icon Vulnrichment

Updated: 2026-05-12T19:02:53.888Z

cve-icon NVD

Status : Modified

Published: 2026-05-12T18:17:30.040

Modified: 2026-05-28T10:16:25.620

Link: CVE-2026-44277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T13:30:15Z

Weaknesses