---
id: CVE-2026-84392
title: >-
  A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet
  FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM
  1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions,
  FortiPAM 1.…
summary: >-
  A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet
  FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM
  1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions,
  FortiPAM 1.…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-476
vendor: Fortinet
product: FortiOS
affected:
  - FortiOS >= 7.4.0 <= 7.4.12
  - FortiOS >= 7.2.0 <= 7.2.13
  - FortiOS >= 7.0.0 <= 7.0.19
  - FortiOS >= 6.4.0 <= 6.4.16
  - FortiProxy >= 7.6.0 <= 7.6.6
  - FortiProxy >= 7.4.0 <= 7.4.14
  - FortiProxy >= 7.2.0 <= 7.2.16
  - FortiPAM 1.9.0
  - FortiPAM >= 1.8.0 <= 1.8.4
  - FortiPAM >= 1.7.0 <= 1.7.2
  - FortiPAM >= 1.6.0 <= 1.6.2
  - FortiPAM >= 1.5.0 <= 1.5.1
  - FortiPAM >= 1.4.0 <= 1.4.3
  - FortiPAM >= 1.3.0 <= 1.3.1
  - FortiPAM 1.2.0
  - FortiPAM >= 1.1.0 <= 1.1.2
  - FortiPAM >= 1.0.0 <= 1.0.3
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:35:10.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84392'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-173'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:28:19.717770Z'
scores:
  nvd: 2.7
  cna: 2.5
ingestedAt: '2026-09-08T19:08:49.602Z'
epss: 0.00281
epssPercentile: 0.20813
---

## Overview

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
