CVE-2026-84386
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter
Exploited
Not listed
EPSS
0.001
3.0th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet
Description
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port.
Weakness: CWE-283
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientWindows
Credit
Fortinet is pleased to thank Robel Campbell from Halcyon and Mirae Yim for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiClientWindows version 8.0.0 or above Upgrade to FortiClientWindows version 7.4.8 or above