Fortinet fixes critical authentication bypass and traffic proxying vulnerabilities
Share
Fortinet has released security patches to address several critical vulnerabilities affecting its product suite, including flaws that allow unauthenticated attackers to bypass authentication and intercept browser traffic.
The most severe defect, tracked as CVE-2026-84390, carries a CVSS score of 9.6. This vulnerability affects the FortiMonitorOnSight web portal and involves the inclusion of sensitive information within the source code. An unauthenticated remote attacker could exploit this flaw to bypass authentication mechanisms by using a forged or reused JSON Web Token (JWT).
A second critical vulnerability, CVE-2026-84388, holds a CVSS score of 9.1 and impacts the Fortinet Privileged Access Agent Chrome extension. If a user visits a malicious website, an unauthenticated attacker could exploit this improper authentication issue to proxy the user’s browser traffic.
Fixing the flaws in the Chrome extension requires coordinated updates across multiple components. Fortinet stated that customers must upgrade FortiPAM to version 1.9.1 or 1.8.4 to secure the environment. Additionally, the Fortinet Privileged Access Agent Chrome extension must be updated to version 8.0.1.123 or higher.
Beyond these critical issues, the company also addressed high-severity vulnerabilities in other core products. These include CVE-2026-26084 in FortiSandbox and CVE-2026-84393 in FortiOS and the FortiProxy Agentless ZTNA portal. The latter could facilitate man-in-the-middle (MitM) attacks, while both could allow unauthorised access to sensitive information.
The patch release also covers several medium- and low-severity issues across a wide range of Fortinet services, including FortiManager, FortiAnalyzer, FortiSOAR, FortiClient for Windows, FortiSIEM, and FortiProxy. Successful exploitation of these various flaws could result in several different security compromises, such as bypassing approval workflows, executing arbitrary code, or causing denial-of-service (DoS) conditions.
Other potential impacts from these additional flaws include the ability to inject broadcast messages, terminate processes, crash the httpsd daemon, or redirect users to arbitrary websites. While the severity of these vulnerabilities is significant, Fortinet has not reported any evidence that these flaws are currently being exploited in the wild.
Security administrators are encouraged to review the company’s PSIRT advisories and apply the necessary updates immediately to mitigate the risk of unauthorised access or traffic interception.




Leave a Reply