PT-2026-7280 · Fortinet · Fortiauthenticator

Published

2026-02-10

·

Updated

2026-02-12

·

CVE-2026-21743

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiAuthenticator versions 6.3 through 6.6.6 Fortinet FortiAuthenticator 6.5 all versions Fortinet FortiAuthenticator 6.4 all versions
Description A missing authorization issue in FortiAuthenticator may allow a user with read-only privileges to modify local user accounts. This is achieved through a file upload to an endpoint that lacks proper protection.
Recommendations FortiAuthenticator versions prior to 6.6.7 should be updated. FortiAuthenticator version 6.5 should be updated. FortiAuthenticator version 6.4 should be updated. FortiAuthenticator version 6.3 should be updated.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-21743

Affected Products

Fortiauthenticator