CVE-2021-24006: Fortinet FortiManager

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

Affected products

  • Fortinet FortiManager: from 6.4.0, before 6.4.4 (fixed in 6.4.4)

Published 2021-09-06. Last modified 2026-06-17.