CVE-2026-44277
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@fortinet.com — https://fortiguard.fortinet.com/psirt/FG-IR-26-128
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| fortinet | fortiauthenticator | {"startIncluding":"6.4.0","endIncluding":"6.4.10"} | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.