NCSC-2026-0197 [1.00] [M/H] Vulnerability fixed in Fortinet FortiPortal
Fortinet has fixed a vulnerability in FortiPortal versions 7.0 to 7.4.7. The vulnerability concerns the FortiPortal API endpoints, where an external attacker with an organizational user role can access sensitive network configuration data via specially crafted HTTP requests. These issues affect the integrity of the access control mechanisms and can lead to exposure of critical network configuration information to unauthorized users.
CSIRTS triage
- What
- An external attacker can access sensitive network configuration data via specially crafted HTTP requests.
- Who is affected
- Organizations using FortiPortal versions 7.0 to 7.4.7 are affected.
- Urgency
- Remediation is urgent due to the potential exposure of critical network configuration information.
- Action
- Upgrade to the patched version of FortiPortal.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiPortal
Get an email when a new FortiPortal advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0197
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-499380.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49938 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownImproper access control in API endpointsfortinet
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21