CVE-2026-84385

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR

Severity
Medium 4.9
CVSS 3.1
Exploited
Not listed
EPSS
0.001
3.5th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet

Description

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiSOAR on-premise
  • Fortinet · FortiSOAR PaaS

Credit

Fortinet is pleased to thank Thomas Sautier for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiSOAR PaaS version 8.0.0 or above Upgrade to FortiSOAR PaaS version 7.6.7 or above Upgrade to FortiSOAR PaaS version 7.5.4 or above Upgrade to FortiSOAR on-premise version 8.0.0 or above Upgrade to FortiSOAR on-premise version 7.6.7 or above Upgrade to FortiSOAR on-premise version 7.5.4 or above

Something wrong here?