Improper Access Control in Fortinet FortiSOAR PaaS and On-Premise Versions
CVE-2026-84385

4.9MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
8 September 2026

What is CVE-2026-84385?

An improper access control vulnerability exists in multiple versions of Fortinet's FortiSOAR PaaS and on-premise products. This security issue may allow an unauthorized attacker to escalate their privileges, potentially gaining access to sensitive data and capabilities of the affected system. It is crucial for users of these FortiSOAR versions to apply available patches and implement security best practices to mitigate the risk of exploitation.

Affected Version(s)

FortiSOAR on-premise 7.6.0 <= 7.6.6

FortiSOAR on-premise 7.5.0 <= 7.5.3

FortiSOAR on-premise 7.4.0 <= 7.4.5

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.