---
id: CVE-2026-44279
title: >-
  An improper export of android application components vulnerability in Fortinet
  FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions,
  FortiTokenAndroid 5.2 all versions may allow attacker to disclose information
  via an e…
summary: >-
  An improper export of android application components vulnerability in Fortinet
  FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions,
  FortiTokenAndroid 5.2 all versions may allow attacker to disclose information
  via an e…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-926
published: '2026-05-12'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44279'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-130'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00139
epssPercentile: 0.02652
ingestedAt: '2026-06-26T16:43:13.642Z'
---

## Overview

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
