CVE-2026-49938

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <in

Severity
Medium 6.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
10.1th percentile
Discovered by
Not disclosed
Published
Jun 9, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiPortal

Vendor remediation

Upgrade to FortiPortal version 7.4.8 or above Upgrade to upcoming FortiPortal version 7.2.9 or above