CVE-2026-44279
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow atta
Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.001
0.8th percentile
Discovered by
Third party
Vendor advisory field
Published
May 12, 2026
Assigned by fortinet
Description
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.
Weakness: CWE-926
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiToken | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiTokenAndroid
Credit
Fortinet is pleased to thank Renan Dias for reporting this vulnerability
Vendor remediation
Upgrade to FortiTokenAndroid version 6.4.0 or above