NULL pointer dereference in Fortinet, Inc products - CVE-2026-84392

 

NULL pointer dereference in Fortinet, Inc products - CVE-2026-84392

Published: September 9, 2026


Vulnerability identifier: #VU148728
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84392
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to perform service disruption.

The vulnerability exists due to null pointer dereference in Log Report. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests.


Affected software

FortiPAM
FortiProxy
FortiOS

How to mitigate CVE-2026-84392

Install update from vendor's website.

FortiPAM - update to 1.9.1
FortiProxy - update to 7.6.7
FortiOS - update to 7.6.0

External References

Related Security Bulletins