SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84385

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Fortinet FortiSOAR PaaS and on-premise versions from 7.3 to 7.6.6 are vulnerable due to improper access control, which could allow attackers to escalate privileges. This vulnerability poses a medium risk, potentially enabling unauthorized access to sensitive functionalities or data. Organizations using affected FortiSOAR versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-84385
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Fortinet

Original NVD Description

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>