CVE-2026-84390

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access con

Severity
Critical 9.6
CVSS 3.1
Exploited
Not listed
EPSS
0.005
43.3th percentile
Discovered by
Not disclosed
Published
Sep 11, 2026
Assigned by fortinet

Description

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

Weakness: CWE-540

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • Fortinet · FortiMonitorOnSight

Vendor remediation

Upgrade to FortiMonitorOnSight version 7.2.8 or above

Something wrong here?