CVE-2026-84390: sensitive information disclosure in Fortinet FortiMonitorOnSight

An attacker may gain improper access to Fortinet FortiMonitorOnSight due to sensitive information included in product source code, tracked as CVE-2026-84390. The issue affects FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. The flaw can enable improper access control decisions because sensitive data in source code may be exposed; vendor guidance and exact attack prerequisites are not specified in the available facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00522
CWE
CWE-540
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: no fix is available for the affected FortiMonitorOnSight releases, so isolate or restrict access to affected instances and monitor for updates from Fortinet until a patch is released.

What is CVE-2026-84390?

An attacker may gain improper access to Fortinet FortiMonitorOnSight due to sensitive information included in product source code, tracked as CVE-2026-84390. The issue affects FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. The flaw can enable improper access control decisions because sensitive data in source code may be exposed; vendor guidance and exact attack prerequisites are not specified in the available facts.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Fortinet FortiMonitorOnSight are affected?

BRANCHAFFECTEDFIXED
7.x7.2.4 – 7.2.7
7.x7.2.0 – 7.2.2

Is CVE-2026-84390 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-84390

  1. Restrict network exposure of FortiMonitorOnSight instances and block external access to management interfaces.
  2. Limit administrative access to trusted hosts and use strong authentication and network segmentation.
  3. Enable and review detailed logging and alerting for unusual access or configuration changes.
  4. Monitor Fortinet advisories and apply vendor-released updates or mitigations as soon as they become available.

Frequently asked questions

Is CVE-2026-84390 being actively exploited?

There are no public reports of exploitation of CVE-2026-84390 as of 2026-09-30.

Which FortiMonitorOnSight versions are affected by CVE-2026-84390?

FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7 are listed as affected.

Is there a patch for CVE-2026-84390?

No patch is available for FortiMonitorOnSight for this vulnerability in the listed affected releases.

What can an attacker do with CVE-2026-84390?

The vulnerability can expose sensitive information in FortiMonitorOnSight source code and may lead to improper access control decisions, potentially allowing unauthorized access or escalation depending on what information is exposed.

References