CVE-2026-49938 PUBLISHED

Assigner: fortinet
Reserved: 02.06.2026 Published: 09.06.2026 Updated: 09.06.2026

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CVSS Score: 6.2

Product Status

Vendor Fortinet
Product FortiPortal
Versions Default: unaffected
  • affected from 7.4.0 to 7.4.7 (incl.)
  • affected from 7.2.0 to 7.2.8 (incl.)
  • affected from 7.0.0 to 7.0.14 (incl.)

Solutions

Upgrade to FortiPortal version 7.4.8 or above Upgrade to upcoming FortiPortal version 7.2.9 or above

References

Problem Types

  • Improper access control CWE