CVE-2026-84390
Received
Received - Intake
Inclusion of Sensitive Information in Fortinet FortiMonitorOnSight
Vulnerability report for CVE-2026-84390, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-11
Last updated on: 2026-09-11
Assigner: Fortinet, Inc.
Description
Description
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortimonitoronsight | From 7.2.4 (inc) to 7.2.7 (inc) |
| fortinet | fortimonitoronsight | From 7.2.0 (inc) to 7.2.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-540 | Source code on a web server or repository often contains sensitive information and should generally not be accessible to users. |