PatchSiren cyber security CVE debrief
CVE-2026-44279 Fortinet CVE debrief
CVE-2026-44279 is a MEDIUM-severity vulnerability affecting Fortinet FortiTokenAndroid versions 5.2, 6.1, and 6.2. An improper export of android application components vulnerability may allow attackers to disclose information via an exported Content Provider URI. The vulnerability was published on May 12, 2026, and modified on June 26, 2026. The CVSS score is 5.5. Fortinet has provided a vendor advisory for mitigation.
- Vendor
- Fortinet
- Product
- FortiTokenAndroid
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-06-26
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-06-26
Who should care
Organizations using Fortinet FortiTokenAndroid versions 5.2, 6.1, and 6.2 should prioritize patching this vulnerability to prevent potential information disclosure. Attackers could exploit this vulnerability to gain unauthorized access to sensitive information. Security teams should review their inventory of affected systems and apply patches or mitigations as recommended by Fortinet.
Technical summary
The vulnerability, CVE-2026-44279, is caused by an improper export of android application components in Fortinet FortiTokenAndroid. This allows attackers to access sensitive information via an exported Content Provider URI. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. The affected versions are 5.2, 6.1, and 6.2 of FortiTokenAndroid. Fortinet has released a vendor advisory (FG-IR-26-130) providing guidance on mitigation.
Defensive priority
Apply patches or mitigations recommended by Fortinet for FortiTokenAndroid versions 5.2, 6.1, and 6.2. Review inventory of affected systems and prioritize patching to prevent potential information disclosure.
Recommended defensive actions
- Apply patches or mitigations recommended by Fortinet for FortiTokenAndroid versions 5.2, 6.1, and 6.2.
- Review inventory of affected systems and prioritize patching.
- Monitor for suspicious activity related to exported Content Provider URIs.
- Implement compensating controls to limit access to sensitive information.
- Exception tracking and monitoring for affected systems.
Evidence notes
The CVE-2026-44279 vulnerability was published on May 12, 2026, and modified on June 26, 2026. The CVSS score is 5.5, and the severity rating is MEDIUM. Fortinet has provided a vendor advisory (FG-IR-26-130) for mitigation. The affected versions are 5.2, 6.1, and 6.2 of FortiTokenAndroid. The vulnerability allows attackers to disclose information via an exported Content Provider URI.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44279 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44279
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44279 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44279
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://fortiguard.fortinet.com/psirt/FG-IR-26-130
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.