CVE-2026-44277
9.8Fortinet · FortiAuthenticator
An improper access control vulnerability in FortiAuthenticator allows unauthenticated attackers to execute unauthorized code or commands.
Executive summary
A critical access control flaw in Fortinet FortiAuthenticator allows unauthenticated remote code execution, posing a severe threat to internal network security.
Vulnerability
The vulnerability involves improper access control (CWE-284) that allows an unauthenticated remote attacker (per CVSS vector PR:N) to execute arbitrary code or commands on the underlying system.
Business impact
The potential for unauthenticated remote code execution makes this a critical risk, as it allows attackers to gain full control over the appliance. Given the CVSS score of 9.8, this could lead to total compromise of identity and authentication services, enabling lateral movement throughout the organization and severe data theft.
Remediation
Immediate Action: Upgrade to FortiAuthenticator version 8.0.3, 8.0.1, 6.6.9, 6.5.7, 6.4.11, or 6.3.5 immediately.
Proactive Monitoring: Monitor system logs for unauthorized administrative logins or unexpected process execution patterns originating from the FortiAuthenticator appliance.
Compensating Controls: Restrict management interface access to trusted IP addresses using firewall rules to limit the exposure of the vulnerable service to untrusted networks.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept repository exists on GitHub.
Analyst recommendation
Due to the unauthenticated nature of this vulnerability and the availability of public proof-of-concept code, this issue represents a high-priority risk. Administrators must prioritize patching these appliances immediately to prevent potential remote system compromise.