Description
A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here>
Published: 2026-05-12
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper export of Android application components in Fortinet FortiTokenAndroid versions 5.2.x, 6.1.x, and 6.2.x may allow an attacker to gain unauthorized access to privileged interfaces or data by exploiting exported activities or services. The vulnerability can lead to the exposure of token credentials or other sensitive data, potentially enabling unauthorized authentication or privilege escalation. This weakness is classified as CWE-926.

Affected Systems

Fortinet FortiTokenAndroid on Android devices is affected in all 5.2.x, 6.1.x, and 6.2.x releases. The issue is mitigated by upgrading to version 6.4.0 or newer.

Risk and Exploitability

We rate the severity with a CVSS score of 5, indicating a medium risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known mass exploit. Based on the description, the flaw appears to be exploitable via local or remote component export, requiring an attacker to trigger an exported activity or service. Since the vector is not explicitly described, the practical exploitability may depend on device configuration and the presence of malicious third‑party applications. Overall, the risk is moderate without a publicly known exploit but could be leveraged by attackers with sufficient Android privilege or a compromised device.

Generated by OpenCVE AI on May 12, 2026 at 20:13 UTC.

Remediation

Vendor Solution

Upgrade to FortiTokenAndroid version 6.4.0 or above


OpenCVE Recommended Actions

  • Upgrade FortiTokenAndroid to version 6.4.0 or newer.
  • Ensure that all Android activity, service, and broadcast receiver components in the application are set to exported="false" unless explicitly required, and that intent filters do not expose sensitive functionality.
  • Apply additional access control checks on token provisioning interfaces so that only authenticated and authorized users can invoke token operations.

Generated by OpenCVE AI on May 12, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 16 May 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet fortitoken Mobile
CPEs cpe:2.3:a:fortinet:fortitoken_mobile:5.2.0:*:*:*:*:android:*:*
cpe:2.3:a:fortinet:fortitoken_mobile:5.2.1:*:*:*:*:android:*:*
cpe:2.3:a:fortinet:fortitoken_mobile:5.2.2:*:*:*:*:android:*:*
cpe:2.3:a:fortinet:fortitoken_mobile:6.1.0:*:*:*:*:android:*:*
cpe:2.3:a:fortinet:fortitoken_mobile:6.2.0:*:*:*:*:android:*:*
Vendors & Products Fortinet fortitoken Mobile

Tue, 12 May 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Allows Unauthorized Access in FortiTokenAndroid

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortitokenandroid
Weaknesses CWE-926
CPEs cpe:2.3:a:fortinet:fortitokenandroid:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitokenandroid:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitokenandroid:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitokenandroid:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitokenandroid:6.2.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortitokenandroid
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortitoken Mobile Fortitokenandroid
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-05-12T19:02:36.321Z

Reserved: 2026-05-05T17:24:18.895Z

Link: CVE-2026-44279

cve-icon Vulnrichment

Updated: 2026-05-12T19:02:31.790Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T18:17:30.330

Modified: 2026-05-16T01:57:41.983

Link: CVE-2026-44279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T01:15:30Z

Weaknesses