PoC Index

CVE-2026-44277

CRITICAL 9.8EPSS 0.6%

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.55% chance of exploitation in the next 30 days, 44th percentile
Published
2026-05-12
Updated
2026-05-28

Proof-of-concept exploits (1)

References

Related