CVE-2026-84386

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector her

Severity
Medium 4.7
CVSS 3.1
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet

Description

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-283

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientWindows

Credit

Fortinet is pleased to thank Robel Campbell from Halcyon and Mirae Yim for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiClientWindows version 8.0.0 or above Upgrade to FortiClientWindows version 7.4.8 or above

Something wrong here?