CVE-2026-49938

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <in

Severity
Medium 6.2
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
25.2th percentile
Discovered by
Third party
Vendor advisory field
Published
Jun 9, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPortal

Credit

External

Vendor remediation

Upgrade to FortiPortal version 7.4.8 or above Upgrade to upcoming FortiPortal version 7.2.9 or above

Something wrong here?