Junglewise Threat Intelligence

CVE-2026-44279: Fortinet FortiTokenAndroid improper export of components in TokenContentProvider

CVE-2026-44279 · Severity: medium · CVSS 5.5 · Published 2026-05-12

Vendors: Fortinet.

Executive brief

FortiTokenAndroid is a mobile application used for two-factor authentication (2FA) to secure logins. A security flaw in the Android app allows other malicious applications installed on the same device to bypass security controls and access one-time password (OTP) codes. This could allow an attacker with a presence on the user's phone to intercept login credentials and gain unauthorized access to protected corporate accounts.

Technical details

An improper export of Android application components (CWE-926) exists in the TokenContentProvider of FortiTokenAndroid. The vulnerability stems from the application incorrectly exposing a Content Provider URI to other apps on the device without sufficient access restrictions. A local attacker with a malicious application installed on the same Android device can query this URI to read OTP codes. This affects versions 5.2, 6.1, and 6.2; users are advised to migrate to version 6.4 or later which is not affected.

Affected products

  • Fortinet FortiTokenAndroid 6.2 all versions, 6.1 all versions, 5.2 all versions

Timeline

  • 2026-05-12: advisory: Initial publication by Fortinet
  • 2026-05-12: disclosed

References