CVE-2026-84391
Awaiting Analysis Awaiting Analysis - Queue

Use of Uninitialized Variable in Fortinet FortiAnalyzer

Vulnerability report for CVE-2026-84391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Fortinet, Inc.

Description

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-09
AI Q&A
2026-09-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fortinet fortianalyzer From 7.6.3 (inc) to 7.6.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-457 The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use of uninitialized variable vulnerability in Fortinet FortiAnalyzer versions 7.6.3 through 7.6.6. It may allow an attacker to cause a denial of service through an unspecified attack vector.

Impact Analysis

The vulnerability could allow an attacker with access to exploit it to disrupt services by causing a denial of service. This may lead to system unavailability or degraded performance.

Mitigation Strategies

Upgrade FortiAnalyzer to a version that patches this vulnerability. Fortinet has not provided specific mitigation steps beyond addressing the issue in newer versions. Monitor Fortinet's security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart