Skip to content
Auto-CTI
Back to today
NEW CRITICAL A2

CVE-2026-84390 , Fortinet FortiMonitor OnSight Information Disclosure Vulnerability

A NVD · · CVE-2026-84390

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
9.8
EPSS
0%

Key insight

Sensitive information hardcoded in source code allows unauthorized access to FortiMonitor instances; vague attack vector details suggest incomplete CVE documentation.

Description

CVE-2026-84390 affects Fortinet FortiMonitor OnSight versions 7.2.0,7.2.7 and is a sensitive information disclosure vulnerability in source code that enables attackers to achieve unauthorized access via improper access control. The NVD documentation is incomplete (attack vector contains a placeholder), indicating ongoing or not-yet-finalized CVE analysis. Fortinet has likely already released or will release updates shortly. Active exploitation status in the wild cannot be determined from available information.

Risk score

100
cvss base
98.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
98.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC