CVE-2021-24006: Fortinet FortiManager
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.
Affected products
- Fortinet FortiManager: from 6.4.0, before 6.4.4 (fixed in 6.4.4)
Published 2021-09-06. Last modified 2026-06-17.