CVE-2026-44277: Authentication Bypass in...FortiAuthenticator

CVSSv3: 9.1

An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Version Affected Solution
FortiAuthenticator 8.0 8.0.2 Upgrade to 8.0.3 or above
FortiAuthenticator 8.0 8.0.0 Upgrade to 8.0.3 or above
FortiAuthenticator 6.6 6.6.0 through 6.6.8 Upgrade to 6.6.9 or above
FortiAuthenticator 6.5 6.5.0 through 6.5.6 Upgrade to 6.5.7 or above

Irony is dead.