
CVE-2026-44277
Fortinet FortiAuthenticatorにおける重大な認証不要のリモートコード実行
CVE-2026-44277 は、Fortinet FortiAuthenticator における重大な脆弱性であり、特定のAPIエンドポイントでの不適切なアクセス制御により、認証不要の攻撃者がリモートコード実行(RCE)を達成できるものです。
| 製品 | 脆弱なバージョン | 修正バージョン |
|---|---|---|
| FortiAuthenticator | 6.5.0 - 6.5.6 | 6.5.7+ |
| FortiAuthenticator | 6.6.0 - 6.6.8 | 6.6.9+ |
| FortiAuthenticator | 8.0.0 - 8.0.2 | 8.0.3+ |
注: FortiAuthenticator Cloudは影響を受けません。
python3 CVE-2026-44277.py http://target-ip
[*] Testing → /api/v1/aaa → Reachable
[!!] Potential vulnerable endpoint found!
[!!] Target is likely vulnerable to CVE-2026-44277
FoFa:
app="Fortinet-FortiAuthenticator"
Shodan:
"FortiAuthenticator" port:443