Missing Authorization in Fortinet FortiClient for Windows - CVE-2026-44278
Published: May 12, 2026
Fortinet FortiClient for Windows
Detailed vulnerability description
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to improper authorization in an unprotected DLL function in the GUI component when decrypting a currently logged in user's VPN password. A local privileged user can invoke the unprotected DLL function to disclose sensitive information.
The issue is limited to the VPN password of a currently logged in user.