A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiA...
Description
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
AI Analyst Comment
Remediation
Update Fortinet FortiAuthenticator to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Fortinet
PRODUCT: FortiAuthenticator
AFFECTED_VERSIONS: 8.0.2, 8.0.0, 6.6.0 through 6.6.8, 6.5.0 through 6.5.6, 6.4.0 through 6.4.10
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An improper access control vulnerability in FortiAuthenticator allows unauthenticated attackers to execute unauthorized code or commands.
Executive Summary:
A critical access control flaw in Fortinet FortiAuthenticator allows unauthenticated remote code execution, posing a severe threat to internal network security.
Vulnerability Details
CVE-ID: CVE-2026-44277
Affected Software: Fortinet FortiAuthenticator
Affected Versions: 8.0.2, 8.0.0, 6.6.0 through 6.6.8, 6.5.0 through 6.5.6, 6.4.0 through 6.4.10
Vulnerability: The vulnerability involves improper access control (CWE-284) that allows an unauthenticated remote attacker (per CVSS vector PR:N) to execute arbitrary code or commands on the underlying system.
Business Impact
The potential for unauthenticated remote code execution makes this a critical risk, as it allows attackers to gain full control over the appliance. Given the CVSS score of 9.8, this could lead to total compromise of identity and authentication services, enabling lateral movement throughout the organization and severe data theft.
Remediation Plan
Immediate Action: Upgrade to FortiAuthenticator version 8.0.3, 8.0.1, 6.6.9, 6.5.7, 6.4.11, or 6.3.5 immediately.
Proactive Monitoring: Monitor system logs for unauthorized administrative logins or unexpected process execution patterns originating from the FortiAuthenticator appliance.
Compensating Controls: Restrict management interface access to trusted IP addresses using firewall rules to limit the exposure of the vulnerable service to untrusted networks.
Exploitation Status
Public Exploit Available: Yes — a public proof-of-concept repository exists on GitHub.
Analyst Notes: As of May 12, 2026, there is no confirmed active exploitation in the wild; however, a public proof-of-concept exists on GitHub, and the vulnerability is highly automatable, making the risk of near-term exploitation significant.
Analyst Recommendation
Due to the unauthenticated nature of this vulnerability and the availability of public proof-of-concept code, this issue represents a high-priority risk. Administrators must prioritize patching these appliances immediately to prevent potential remote system compromise.