Improper access control in API endpoints
CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00
CSIRTS triage
- What
- Improper access control in API endpoints may allow sensitive data exposure.
- Who is affected
- Organizations using FortiPortal are affected.
- Urgency
- Remediation is high urgency due to the risk of sensitive data exposure.
- Action
- Implement access controls and monitor API usage.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiPortal
Get an email when a new FortiPortal advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-140
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-499380.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49938 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Improper access control
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to secur…nvd · 2026-08-25
- unknownCVE-2026-79201: Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote at…nvd · 2026-08-25
- highCVE-2026-61419: Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerabili…nvd · 2026-08-24
- criticalexploitedCVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabil…cisa-kev · 2026-08-24
- mediumCVE-2026-34836: Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access contro…nvd · 2026-08-21
- mediumCVE-2026-66797: Improper access control in CloudStack's annotation functionality allows unauthorized comment c…nvd · 2026-08-21
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownBroken access control in the RADIUS type admin group2026-08-12
- unknownUI DoS attack2026-08-12