CVE-2026-84390
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access con
Severity
Critical 9.6
CVSS 3.1
Exploited
Not listed
EPSS
0.005
43.3th percentile
Discovered by
Not disclosed
Published
Sep 11, 2026
Assigned by fortinet
Description
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>
Weakness: CWE-540
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported products (1)
- Fortinet · FortiMonitorOnSight
Vendor remediation
Upgrade to FortiMonitorOnSight version 7.2.8 or above