---
id: CVE-2026-84386
title: >-
  A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0
  through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to
  improper access control via <insert attack vector here>
summary: >-
  A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0
  through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to
  improper access control via <insert attack vector here>
severity: medium
cvss: 5.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-283
vendor: Fortinet
product: FortiClientWindows
affected:
  - FortiClientWindows >= 7.4.0 <= 7.4.7
  - FortiClientWindows >= 7.2.0 <= 7.2.15
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:35:10.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84386'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-165'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:42:21.974285Z'
scores:
  nvd: 5.1
  cna: 4.7
ingestedAt: '2026-09-08T19:08:49.602Z'
epss: 0.00143
epssPercentile: 0.02954
---

## Overview

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
