CVE-2026-84391

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

Severity
Medium 5.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.7th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet

Description

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

Weakness: CWE-457

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiAnalyzer

Credit

Fortinet is pleased to thank Stefan Grosser from Zebbra AG and Ralph Grossenbacher from BIT for reporting this vulnerability under responsible disclosure

Vendor remediation

Upgrade to FortiAnalyzer version 8.0.0 or above Upgrade to FortiAnalyzer version 7.6.7 or above

Something wrong here?