Fortinet / FortiAuthenticator
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-53379 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated a… | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-44277 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthentica… | CRITICAL | 9.8 | May 12, 2026 |
| CVE-2026-21743 | A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versi… | HIGH | 7.2 | Feb 10, 2026 |
| CVE-2025-57823 | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator… | LOW | 2.7 | Dec 9, 2025 |
| CVE-2025-59923 | An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all ve… | LOW | 2.7 | Dec 9, 2025 |
| CVE-2022-23439 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, whe… | MEDIUM | 6.1 | Jan 22, 2025 |
| CVE-2024-23664 | A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow… | MEDIUM | 6.1 | Jun 3, 2024 |
| CVE-2022-22302 | A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.… | MEDIUM | 5.3 | Jul 11, 2023 |
| CVE-2022-35850 | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6… | MEDIUM | 6.1 | Apr 11, 2023 |
| CVE-2023-26208 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthentic… | MEDIUM | 5.3 | Mar 9, 2023 |
| CVE-2021-26116 | An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow… | HIGH | 8.8 | Apr 6, 2022 |
| CVE-2021-36177 | An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan… | MEDIUM | 4.3 | Feb 2, 2022 |
| CVE-2021-43068 | A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. | HIGH | 8.1 | Dec 9, 2021 |
| CVE-2021-43067 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, ve… | HIGH | 8.3 | Dec 8, 2021 |
| CVE-2021-22124 | An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0… | HIGH | 7.5 | Aug 4, 2021 |
| CVE-2021-24005 | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with acc… | HIGH | 7.5 | Jul 6, 2021 |
| CVE-2019-16154 | An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scr… | MEDIUM | 6.1 | Jan 7, 2020 |
| CVE-2018-9186 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to e… | MEDIUM | 6.1 | May 31, 2018 |
| CVE-2015-1459 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation… | MEDIUM | 4.3 | Feb 3, 2015 |
| CVE-2015-1458 | Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access… | MEDIUM | 6.9 | Feb 3, 2015 |
| CVE-2015-1457 | Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command. | MEDIUM | 4.9 | Feb 3, 2015 |
| CVE-2015-1456 | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information… | MEDIUM | 4.0 | Feb 3, 2015 |
| CVE-2015-1455 | Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it e… | HIGH | 7.5 | Feb 3, 2015 |
| CVE-2013-6990 | FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. | HIGH | 9.0 | Apr 30, 2014 |
Showing 1 to 24 of 24 CVEs