SB2026090977 - Unverified Ownership in Fortinet FortiClient for Windows



SB2026090977 - Unverified Ownership in Fortinet FortiClient for Windows

Published: September 9, 2026

Security Bulletin ID SB2026090977
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Unverified Ownership (CVE-ID: CVE-2026-84386)

CWE-ID: CWE-283 - Unverified Ownership

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to damange or delete data.

The vulnerability exists due to unverified ownership. An authenticated attacker can terminate arbitrary processes via an exposed minifilter communication port.


Remediation

Install update from vendor's website.