CVE-2026-84386
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H/E:P/RL:O/RC:C
- EPSS probability
- 0.10%
- CWE
- CWE-283
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Fortinet FortiClientWindows
- Fortinet FortiClientWindows
Weakness type
Related vulnerabilities
- CVE-2026-87913 — Missing S3 bucket ownership verification in the AWS Security Agent MCP server
- CVE-2026-87912 — Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
- CVE-2026-85781 — Unverified access point ownership in Amazon EFS CSI Driver
- CVE-2026-9745 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-54467 — On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on...
- CVE-2026-15599 — Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
- CVE-2026-44707 — Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
- CVE-2026-44562 — Open WebUI: Model Import Overwrites Any Model Without Ownership Check