---
cve: "CVE-2026-44279"
severity: "MEDIUM"
cvss: 5.0
epss: "10%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2026-05-12 18:17:30"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T16:08:12+02:00"
---

# CVE-2026-44279

> 5.0 MEDIUM

## Beschreibung

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-26-130>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-44279) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
