Decoding the world of cybersecurity

Fortinet fixes privileged access weaknesses

Fortinet has patched critical vulnerabilities affecting FortiMonitorOnSight and its Privileged Access Agent Chrome extension, including authentication bypass and browser-traffic proxy risks.

Fortinet fixes privileged access weaknesses
Summary
  • CVE-2026-84390 can allow unauthenticated attackers to bypass FortiMonitorOnSight authentication using forged or reused JWTs.
  • CVE-2026-84388 affects the Privileged Access Agent browser extension and can allow an attacker to proxy browser traffic.
  • Current vendor and government advisories do not establish active exploitation of the two flaws.

Fortinet has patched two critical vulnerabilities affecting monitoring and privileged-access technology, including an authentication bypass in FortiMonitorOnSight and a browser-extension weakness capable of proxying a user’s web traffic.

CVE-2026-84390 affects the FortiMonitorOnSight web portal and carries a CVSS score of 9.6. Fortinet describes the issue as sensitive information included in source code, allowing a remote unauthenticated attacker to bypass authentication using a forged or reused JSON Web Token.

The affected FortiMonitorOnSight releases include versions in the 7.2 branch identified by Fortinet’s September advisory. Canada’s Cyber Centre included the product in a 9 September security notice and advised administrators to review Fortinet’s PSIRT material and apply the necessary updates.

The second critical issue, CVE-2026-84388, affects Fortinet’s Privileged Access Agent Chrome extension. It carries a CVSS score of 9.1 and can allow a remote unauthenticated attacker to proxy a user’s browser traffic if the user visits a malicious website.

The browser-extension flaw is significant because the affected component participates in privileged-access workflows rather than ordinary browsing. Fortinet’s privileged-access architecture uses browser and proxy functions to mediate access to protected resources, placing the extension close to the boundary between an authenticated user and sensitive administrative systems.

A vulnerability in that layer does not establish that an attacker can automatically steal every privileged credential or compromise every downstream service. The confirmed impact is narrower: browser traffic can be proxied under the conditions described by Fortinet. Any further consequences depend on the applications, sessions and controls present in the affected environment.

The same discipline applies to CVE-2026-84390. A successful authentication bypass gives an attacker access that should have been denied, but the precise downstream impact depends on the functions and data exposed through the FortiMonitorOnSight deployment.

Both vulnerabilities nevertheless affect products organisations rely upon to monitor or control access to other systems. Security tooling accumulates trust because it needs visibility and privilege to perform its function. That can increase the value of compromising it compared with a conventional end-user application.

Fortinet’s September cycle also addresses other vulnerabilities across its product portfolio, including FortiOS, FortiProxy and FortiSandbox. The number of affected products creates an asset-management requirement before remediation begins: organisations need to establish which Fortinet components and extension versions they actually operate rather than treating the release as a single appliance update.

There is no confirmed evidence in the sources reviewed for this article that CVE-2026-84390 or CVE-2026-84388 is being exploited in the wild. Severity and exploitation status should therefore remain separate. Both flaws are rated critical, but the current response is preventative patching rather than containment of a confirmed campaign.

That distinction can disappear quickly for security infrastructure once technical details become widely available. Management and privileged-access products expose functionality that is attractive after compromise, and internet-reachable administrative interfaces have repeatedly become targets across the wider enterprise-security market.

Fortinet has released remediation guidance for the affected products. Organisations operating the browser extension also need to consider the surrounding FortiPAM environment, because privileged-access components are deployed as part of a wider control chain rather than in isolation.

×