VDB
CVE-2026-84385
CVE-2026-84385
PUBLISHED
CVSS 4.9 MEDIUM
Reported by fortinet · Published September 8, 2026
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>
Risk Scores
CVSS 3.1
4.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiSOAR on-premise | 7.6.0, 7.5.0, 7.4.0 |
| Fortinet | FortiSOAR PaaS | 7.6.0, 7.5.0, 7.4.0 |
| Fortinet | FortiSOAR on-premise | 7.3.0, 7.6.0, 7.5.0 |
| Fortinet | FortiSOAR PaaS | 7.6.0, 7.5.0, 7.4.0 |
Timeline
- Sep 8, 2026 Coalition ESS Score
- Sep 8, 2026 CVE Published
- Sep 8, 2026 CVE Updated