Unverified Ownership Vulnerability in Fortinet FortiClient
CVE-2026-84386

4.7MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
8 September 2026

What is CVE-2026-84386?

An unverified ownership vulnerability exists in certain versions of Fortinet FortiClient, specifically Windows versions 7.4.0 to 7.4.7 and all versions of 7.2. This flaw could permit attackers to gain improper access control, posing a serious risk to the security and integrity of the affected systems. It is critical for users of these FortiClient versions to apply necessary patches and updates to mitigate this potential threat.

Affected Version(s)

FortiClientWindows 7.4.0 <= 7.4.7

FortiClientWindows 7.2.0 <= 7.2.15

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.