CVE-2023-44249: Fortinet Fortianalyzer

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.

Affected products

  • Fortinet Fortianalyzer: from 6.2.0, up to and including 6.2.12; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.9; from 7.2.0, before 7.2.4 (fixed in 7.2.4); version 7.4.0 only
  • Fortinet FortiManager: from 6.2.0, up to and including 6.2.12; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.9; from 7.2.0, before 7.2.4 (fixed in 7.2.4); version 7.4.0 only

Published 2023-10-10. Last modified 2026-06-17.