CVE-2026-84385: Fortinet Fortisoar On-Premise

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>

Affected products

  • Fortinet Fortisoar On-Premise: from 7.6.0, up to and including 7.6.6; from 7.5.0, up to and including 7.5.3; from 7.4.0, up to and including 7.4.5; from 7.3.0, up to and including 7.3.3
  • Fortinet Fortisoar Paas: from 7.6.0, up to and including 7.6.6; from 7.5.0, up to and including 7.5.3; from 7.4.0, up to and including 7.4.5; from 7.3.0, up to and including 7.3.3

Published 2026-09-08. Last modified 2026-09-10.