> Improper access control on API endpoints
[DATE: 12/05/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
9.1
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Revised on 2026-05-12 00:00:00