CVE-2026-84386
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector her
Severity
Medium 4.7
CVSS 3.1
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet
Description
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>
Weakness: CWE-283
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientWindows
Credit
Fortinet is pleased to thank Robel Campbell from Halcyon and Mirae Yim for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiClientWindows version 8.0.0 or above Upgrade to FortiClientWindows version 7.4.8 or above