6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
Description
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.
Basic Information
ID
CVE-2026-21743
Source
fortinet
Published
Feb 10, 2026 at 15:39
Modified
Feb 10, 2026 at 16:26
Affected Product
Vendor
Fortinet
Product
FortiAuthenticator
Version
6.6.0
Affected Versions
Fortinet FortiAuthenticator 6.6.0
Fortinet FortiAuthenticator 6.5.0
Fortinet FortiAuthenticator 6.4.0
Fortinet FortiAuthenticator 6.3.0
Fortinet FortiAuthenticator 6.5.0
Fortinet FortiAuthenticator 6.4.0
Fortinet FortiAuthenticator 6.3.0