
CVE-2026-44277
Fortinet FortiAuthenticator의 중요 인증되지 않은 원격 코드 실행
CVE-2026-44277은 Fortinet FortiAuthenticator의 중요 취약점으로, 특정 API 엔드포인트에서 부적절한 접근 제어를 통해 인증되지 않은 공격자가 원격 코드 실행(RCE)을 달성할 수 있습니다.
| 제품 | 취약한 버전 | 수정 버전 |
|---|---|---|
| FortiAuthenticator | 6.5.0 - 6.5.6 | 6.5.7+ |
| FortiAuthenticator | 6.6.0 - 6.6.8 | 6.6.9+ |
| FortiAuthenticator | 8.0.0 - 8.0.2 | 8.0.3+ |
참고: FortiAuthenticator Cloud는 영향을 받지 않습니다.
python3 CVE-2026-44277.py http://target-ip
[*] Testing → /api/v1/aaa → Reachable
[!!] Potential vulnerable endpoint found!
[!!] Target is likely vulnerable to CVE-2026-44277
FoFa:
app="Fortinet-FortiAuthenticator"
Shodan:
"FortiAuthenticator" port:443