Junglewise Threat Intelligence

CVE-2026-49938: Fortinet FortiPortal improper access control in API endpoints

CVE-2026-49938 · Severity: medium · CVSS 6.5 · Published 2026-06-09

Vendors: Fortinet.

Executive brief

FortiPortal is a management console used by service providers and enterprises to manage security policies and network devices. A security flaw in its programming interface could allow an authorized user within an organization to access sensitive network configuration details they are not supposed to see. This could lead to the exposure of internal network architecture and security settings to unauthorized personnel.

Technical details

An improper access control vulnerability (CWE-284) exists in the API endpoints of Fortinet FortiPortal. The flaw allows a remote privileged attacker with an 'organization user' role to bypass intended access restrictions by sending specifically crafted HTTP requests. Successful exploitation enables the attacker to retrieve sensitive network configuration data that should be restricted based on their role. The vulnerability affects FortiPortal versions 7.4.0-7.4.7, 7.2.0-7.2.8, and all 7.0 versions. Users are advised to upgrade to versions 7.4.8, 7.2.9, or migrate from the 7.0 branch to a supported fixed release.

Affected products

  • Fortinet FortiPortal 7.4.0 through 7.4.7, 7.2.0 through 7.2.8, 7.0 all versions

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References