Missing authorization on CSV user import

Summary

A missing authorization vulnerability [CWE-862] in FortiAuthenticator may allow a read-only admin to make modification to local users via a file upload to an unprotected endpoint.

Version Affected Solution
FortiAuthenticator 8.0 Not affected Not Applicable
FortiAuthenticator 6.6 6.6.0 through 6.6.6 Upgrade to 6.6.7 or above
FortiAuthenticator 6.5 6.5 all versions Migrate to a fixed release
FortiAuthenticator 6.4 6.4 all versions Migrate to a fixed release
FortiAuthenticator 6.3 6.3 all versions Migrate to a fixed release

Acknowledgement

Discovered during an independent audit commissioned by Fortinet.

Timeline

2026-02-10: Initial publication