PT-2026-7280 · Fortinet · Fortiauthenticator
Published
2026-02-10
·
Updated
2026-02-12
·
CVE-2026-21743
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiAuthenticator versions 6.3 through 6.6.6
Fortinet FortiAuthenticator 6.5 all versions
Fortinet FortiAuthenticator 6.4 all versions
Description
A missing authorization issue in FortiAuthenticator may allow a user with read-only privileges to modify local user accounts. This is achieved through a file upload to an endpoint that lacks proper protection.
Recommendations
FortiAuthenticator versions prior to 6.6.7 should be updated.
FortiAuthenticator version 6.5 should be updated.
FortiAuthenticator version 6.4 should be updated.
FortiAuthenticator version 6.3 should be updated.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiauthenticator