---
id: CVE-2026-84390
title: >-
  A inclusion of sensitive information in source code vulnerability in Fortinet
  FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through
  7.2.2 may allow attacker to improper access control via <insert attack vector
  here>
summary: >-
  A inclusion of sensitive information in source code vulnerability in Fortinet
  FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through
  7.2.2 may allow attacker to improper access control via <insert attack vector
  here>
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-540
vendor: Fortinet
product: FortiMonitorOnSight
affected:
  - FortiMonitorOnSight >= 7.2.4 <= 7.2.7
  - FortiMonitorOnSight >= 7.2.0 <= 7.2.2
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T18:24:59.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84390'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-170'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T12:44:29.513668Z'
scores:
  nvd: 9.8
  cna: 9.6
ingestedAt: '2026-09-13T09:30:47.014Z'
epss: 0.00522
epssPercentile: 0.4186
---

## Overview

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
