Fortinet Fortiauthenticator vulnerabilities
24 known vulnerabilities affecting fortinet/fortiauthenticator.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM12LOW3
Vulnerabilities
Page 1 of 2
CVE-2026-44277P2CRITICALCVSS 9.8≥ 6.4.0, ≤ 6.4.10≥ 6.5.0, < 6.5.7+6 more2026-05-12
CVE-2026-44277 [CRITICAL] CWE-284 CVE-2026-44277: A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
nvd
CVE-2021-26116P3HIGHCVSS 8.8≥ 5.0.0, < 6.3.12022-04-06
CVE-2021-26116 [HIGH] CWE-78 CVE-2021-26116: An improper neutralization of special elements used in an OS command vulnerability in the command li
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
nvd
CVE-2021-43068P3HIGHCVSS 8.1v6.4.02021-12-09
CVE-2021-43068 [HIGH] CWE-287 CVE-2021-43068: A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the sec
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
nvd
CVE-2025-53379P3HIGHCVSS 7.5≥ 6.5.0, ≤ 6.5.7≥ 6.6.0, ≤ 6.6.2+2 more2026-07-14
CVE-2025-53379 [HIGH] CWE-125 CVE-2025-53379: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenti
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
nvd
CVE-2026-21743P3HIGHCVSS 7.2≥ 6.3.0, < 6.6.7≥ 6.6.0, ≤ 6.6.6+3 more2026-02-10
CVE-2026-21743 [HIGH] CWE-862 CVE-2026-21743: A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthe
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.
nvd
CVE-2013-6990P3CRITICALCVSS 9.0≤ 2.22014-04-30
CVE-2013-6990 [CRITICAL] CWE-264 CVE-2013-6990: FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the com
FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
nvd
CVE-2021-22124P3HIGHCVSS 7.5≥ 4.0.0, ≤ 4.3.4≥ 5.0.0, ≤ 5.5.0+1 more2021-08-04
CVE-2021-22124 [HIGH] CWE-400 CVE-2021-22124: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of Forti
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
nvd
CVE-2015-1455P3HIGHCVSS 7.5v3.0.02015-02-03
CVE-2015-1455 [HIGH] CWE-255 CVE-2015-1455: Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2)
Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.
nvd
CVE-2021-24005P3HIGHCVSS 7.5≥ 6.0.0, < 6.3.0vFortiAuthenticator versions before 6.3.0.2021-07-06
CVE-2021-24005 [HIGH] CWE-798 CVE-2021-24005: Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthent
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key.
nvd
CVE-2021-43067P4MEDIUMCVSS 6.5≥ 6.0.1, ≤ 6.0.7v6.1.0+8 more2021-12-08
CVE-2021-43067 [MEDIUM] CWE-200 CVE-2021-43067: A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version
A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 factors authentication token via crafted HTTP requests.
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 6.3.0, < 6.3.4≥ 6.4.0, < 6.4.2+10 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2023-26208P4MEDIUMCVSS 5.3≥ 5.4.0, < 6.5.0≥ 6.4.0, ≤ 6.4.6+4 more2023-03-09
CVE-2023-26208 [MEDIUM] CWE-307 CVE-2023-26208: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet Fort
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
nvd
CVE-2024-23664P4MEDIUMCVSS 6.1≥ 6.4.0, < 6.5.4v6.6.0+2 more2024-06-03
CVE-2024-23664 [MEDIUM] CWE-601 CVE-2024-23664: A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0,
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
nvd
CVE-2019-16154P4MEDIUMCVSS 6.1v6.0.02020-01-07
CVE-2019-16154 [MEDIUM] CWE-79 CVE-2019-16154: An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 ma
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
nvd
CVE-2022-35850P4MEDIUMCVSS 6.1≥ 6.1.0, < 6.3.4≥ 6.4.0, < 6.4.7+4 more2023-04-11
CVE-2022-35850 [MEDIUM] CWE-80 CVE-2022-35850: An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in Forti
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page.
nvd
CVE-2018-9186P4MEDIUMCVSS 6.1≥ 4.0.0, < 5.3.02018-05-31
CVE-2018-9186 [MEDIUM] CWE-79 CVE-2018-9186: A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to befor
A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header.
nvd
CVE-2015-1458P4MEDIUMCVSS 6.9v3.0.02015-02-03
CVE-2015-1458 [MEDIUM] CWE-264 CVE-2015-1458: Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privil
Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command.
nvd
CVE-2021-36177P4MEDIUMCVSS 4.3≥ 6.0.0, < 6.3.32022-02-02
CVE-2021-36177 [MEDIUM] CVE-2021-36177: An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below,
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.
nvd
CVE-2015-1457P4MEDIUMCVSS 4.9v3.0.02015-02-03
CVE-2015-1457 [MEDIUM] CWE-200 CVE-2015-1457: Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.
nvd
CVE-2015-1459P4MEDIUMCVSS 4.3v3.0.02015-02-03
CVE-2015-1459 [MEDIUM] CWE-79 CVE-2015-1459: Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attacker
Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.
nvd
1 / 2Next →