CVE-2026-21743: High severity Fortinet FortiAuthenticator vulnerability
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21743?
CVE-2026-21743 has been classified with a medium severity due to the potential for unauthorized modifications by low-privileged users.
How do I fix CVE-2026-21743?
To fix CVE-2026-21743, upgrade Fortinet FortiAuthenticator to version 6.6.7 or later, or to version 6.5.1 or later.
Who is affected by CVE-2026-21743?
CVE-2026-21743 affects users of Fortinet FortiAuthenticator versions 6.3 through 6.6.6 and all versions of 6.5 and 6.4.
What type of vulnerability is CVE-2026-21743?
CVE-2026-21743 is categorized as a missing authorization vulnerability, which allows unintended modifications by unauthorized users.
Can CVE-2026-21743 lead to data breaches?
Yes, CVE-2026-21743 could potentially lead to data breaches if an attacker exploits the vulnerability to modify user accounts or access sensitive information.