CVE-2026-84390
Fortinet FortiMonitorOnSight software versions 7.2.0‑7.2.2 and 7.2.4‑7.2.7 contain a flaw where sensitive information is embedded in the source code. This can lead to improper access control, potentially allowing attackers to gain unauthorized access. The vulnerability is critical because it requires no authentication and can compromise confidentiality, integrity, and availability.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Fortinet FortiMonitorOnSight 7.2.0‑7.2.2 and 7.2.4‑7.2.7.
Real-world impact
An attacker could exploit the exposed sensitive data to bypass access controls and gain unauthorized access to the FortiMonitorOnSight system, potentially reading or modifying data, or disrupting services.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited over the network without authentication, and it can fully compromise confidentiality, integrity, and availability. The high impact and ease of exploitation make it a critical vulnerability.
What to do about it
- ›Monitor Fortinet advisories for a patch.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.