ZeroHour

CVE-2026-84390

niche

Sensitive Information in Source Code in Fortinet FortiMonitorOnSight (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-84390 is a critical (CVSS 3.1: 9.8) information-disclosure flaw in Fortinet FortiMonitorOnSight in which sensitive information is included in the product's source code (CWE-540). An unauthenticated, network-located attacker who obtains that embedded material (e.g., secrets or credentials shipped with the code) can use it to gain improper access by subverting access controls; the CVSS vector requires no privileges or user interaction and rates the impact high on confidentiality, integrity, and availability. All FortiMonitorOnSight deployments running the affected 7.2.x releases listed by Fortinet (7.2.0 through 7.2.2 and 7.2.4 through 7.2.7) are affected. Fortinet has shipped fixes for this flaw, but there is no public proof-of-concept, the vulnerability is not in CISA KEV, and no exploitation in the wild is currently known.

What to do: Upgrade FortiMonitorOnSight to a fixed release per Fortinet's PSIRT advisory, i.e., any version superseding the listed 7.2.0-7.2.2 and 7.2.4-7.2.7 ranges. Because the flaw involves sensitive material in source code, also rotate any credentials, keys, or secrets associated with the deployment and review logs for signs of unauthenticated access. Until patched, restrict network exposure of the OnSight management interface to trusted networks only.

Affected
Fortinet FortiMonitorOnSight7.2.0 through 7.2.2
Fortinet FortiMonitorOnSight7.2.4 through 7.2.7
Estimated exposure
nichelikely on the order of a few thousand deployments worldwide (estimate; no public install counts) — FortiMonitorOnSight is a niche Fortinet remote-monitoring product line with a far smaller install base than flagship products like FortiGate, and no public install or internet-scan counts exist, so the figure reflects deployment patterns…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via

Weakness
CWE-540
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.