CVE-2026-44279: Medium severity Fortinet FortiTokenAndroid vulnerability
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiTokenAndroidto a version that resolves this vulnerability.Fixed in 6.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44279?
CVE-2026-44279 is rated as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2026-44279?
To fix CVE-2026-44279, users should update Fortinet FortiTokenAndroid to the latest version.
Which versions of Fortinet FortiTokenAndroid are affected by CVE-2026-44279?
CVE-2026-44279 affects all versions of Fortinet FortiTokenAndroid 6.2, 6.1, and 5.2.
What types of attacks can exploit CVE-2026-44279?
CVE-2026-44279 can be exploited through improper access control methods.
Is there a workaround for CVE-2026-44279?
Currently, the recommended mitigation for CVE-2026-44279 is to apply the available software updates from Fortinet.