CVE-2026-49938
Fortinet has fixed a vulnerability in FortiPortal versions 7.0 to 7.4.7. The vulnerability concerns the FortiPortal API endpoints, where an external attacker with an organizational user role can access sensitive network configuration data via specially crafted HTTP requests. These issues affect the integrity of the access control mechanisms and can lead to exposure of critical network configuration information to unauthorized users.
CSIRTS triage
- What
- An external attacker can access sensitive network configuration data via specially crafted HTTP requests.
- Who is affected
- Organizations using FortiPortal versions 7.0 to 7.4.7 are affected.
- Urgency
- Remediation is urgent due to the potential exposure of critical network configuration information.
- Action
- Upgrade to the patched version of FortiPortal.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-49938
Get an email if CVE-2026-49938 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0197 [1.00] [M/H] Vulnerability fixed in Fortinet FortiPortalncsc-nl · 2026-06-12
- unknownImproper access control in API endpointsfortinet · 2026-06-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-49938)