
CVE-2026-44277
Fortinet FortiAuthenticator में महत्वपूर्ण अनधिकृत दूरस्थ कोड निष्पादन
CVE-2026-44277 Fortinet FortiAuthenticator में एक महत्वपूर्ण कमजोरी है जो अनधिकृत हमलावरों को विशिष्ट API एंडपॉइंट पर अनुचित पहुंच नियंत्रण के माध्यम से दूरस्थ कोड निष्पादन (RCE) प्राप्त करने की अनुमति देती है।
| उत्पाद | कमजोर संस्करण | सुरक्षित संस्करण |
|---|---|---|
| FortiAuthenticator | 6.5.0 - 6.5.6 | 6.5.7+ |
| FortiAuthenticator | 6.6.0 - 6.6.8 | 6.6.9+ |
| FortiAuthenticator | 8.0.0 - 8.0.2 | 8.0.3+ |
नोट: FortiAuthenticator Cloud प्रभावित नहीं है।
python3 CVE-2026-44277.py http://target-ip
[*] Testing → /api/v1/aaa → Reachable
[!!] Potential vulnerable endpoint found!
[!!] Target is likely vulnerable to CVE-2026-44277
FoFa:
app="Fortinet-FortiAuthenticator"
Shodan:
"FortiAuthenticator" port:443