CVE-2026-44277: Critical severity Fortinet FortiAuthenticator vulnerability
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44277?
CVE-2026-44277 is considered a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-44277?
To fix CVE-2026-44277, upgrade Fortinet FortiAuthenticator to the latest available version that addresses the vulnerability.
What versions of Fortinet FortiAuthenticator are affected by CVE-2026-44277?
CVE-2026-44277 affects FortiAuthenticator versions 8.0.2, 8.0.0, 6.6.0 through 6.6.8, and 6.5.0 through 6.5.6.
What is the nature of the vulnerability in CVE-2026-44277?
CVE-2026-44277 is an improper access control vulnerability that may allow an attacker to execute unauthorized code or commands.
Can CVE-2026-44277 be exploited remotely?
Yes, CVE-2026-44277 can potentially be exploited remotely due to its remote code execution capabilities.