CVE-2026-84385 PUBLISHED

Assigner: fortinet
Reserved: 01.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
CVSS Score: 4.9

Product Status

Vendor Fortinet
Product FortiSOAR on-premise
Versions Default: unaffected
  • affected from 7.6.0 to 7.6.6 (incl.)
  • affected from 7.5.0 to 7.5.3 (incl.)
  • affected from 7.4.0 to 7.4.5 (incl.)
  • affected from 7.3.0 to 7.3.3 (incl.)
Vendor Fortinet
Product FortiSOAR PaaS
Versions Default: unaffected
  • affected from 7.6.0 to 7.6.6 (incl.)
  • affected from 7.5.0 to 7.5.3 (incl.)
  • affected from 7.4.0 to 7.4.5 (incl.)
  • affected from 7.3.0 to 7.3.3 (incl.)

Solutions

Upgrade to FortiSOAR PaaS version 8.0.0 or above Upgrade to FortiSOAR PaaS version 7.6.7 or above Upgrade to FortiSOAR PaaS version 7.5.4 or above Upgrade to FortiSOAR on-premise version 8.0.0 or above Upgrade to FortiSOAR on-premise version 7.6.7 or above Upgrade to FortiSOAR on-premise version 7.5.4 or above

References

Problem Types

  • Escalation of privilege CWE