Authorization Vulnerability in Fortinet FortiAuthenticator Software
CVE-2026-21743
6.8MEDIUM
What is CVE-2026-21743?
A missing authorization vulnerability in Fortinet's FortiAuthenticator allows a read-only user to modify local user accounts through an unprotected file upload endpoint. This issue affects multiple versions of FortiAuthenticator, posing risks for unauthorized access and potential manipulation of local user settings.
Affected Version(s)
FortiAuthenticator 6.6.0 <= 6.6.6
FortiAuthenticator 6.5.0 <= 6.5.7
FortiAuthenticator 6.4.0 <= 6.4.11