CVE-2026-21743: Fortinet Fortiauthenticator
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.
Affected products
- Fortinet Fortiauthenticator: from 6.3.0, before 6.6.7 (fixed in 6.6.7)
Published 2026-02-10. Last modified 2026-06-17.