
CVE-2026-44277
ثغرة تنفيذ أوامر عن بُعد غير مصادق عليه حرجة في Fortinet FortiAuthenticator
CVE-2026-44277 هي ثغرة أمنية حرجة في Fortinet FortiAuthenticator تسمح للمهاجمين غير المصادق عليهم بتنفيذ أوامر عن بُعد (RCE) عبر التحكم غير السليم في الوصول إلى نقاط نهاية API محددة.
| المنتج | الإصدارات المتأثرة | الإصدارات المُصلحة |
|---|---|---|
| FortiAuthenticator | 6.5.0 - 6.5.6 | 6.5.7+ |
| FortiAuthenticator | 6.6.0 - 6.6.8 | 6.6.9+ |
| FortiAuthenticator | 8.0.0 - 8.0.2 | 8.0.3+ |
ملاحظة: FortiAuthenticator Cloud غير متأثر.
python3 CVE-2026-44277.py http://target-ip
[*] Testing → /api/v1/aaa → Reachable
[!!] Potential vulnerable endpoint found!
[!!] Target is likely vulnerable to CVE-2026-44277
FoFa:
app="Fortinet-FortiAuthenticator"
Shodan:
"FortiAuthenticator" port:443