Description
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>
Published: 2026-09-08
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch or Upgrade
AI Analysis

Impact

A flaw that allows an attacker to bypass standard ownership checks within Fortinet FortiClientWindows could enable unauthorized access to protected resources. The vulnerability is classified as an access control weakness, permitting an authenticated or unauthenticated user to perform actions or access data that should be restricted. Because the description indicates improper access control, the potential consequences include data exposure, escalation of privileges, or compromise of system integrity for the affected client installations.

Affected Systems

The vulnerability impacts Fortinet FortiClientWindows version 7.4.0 through 7.4.7 and all releases of the 7.2.x branch, including 7.2.0‑7.2.15. Users running these versions on Windows environments are at risk unless they upgrade or apply a patch.

Risk and Exploitability

The CVSS score of 4.7 signals a moderate risk level, yet the absence of an EPSS score means the likelihood of exploitation is currently unknown. Fortinet has not listed the issue in the CISA KEV catalog, suggesting that no widespread exploitation has been documented. The address vectors are not publicly disclosed; it is inferred that the vulnerability may be triggered through local or remote access mechanisms that involve unverified ownership verification, but specific attack conditions remain unspecified.

Generated by OpenCVE AI on September 8, 2026 at 18:02 UTC.

Remediation

Vendor Solution

Upgrade to FortiClientWindows version 8.0.0 or above Upgrade to FortiClientWindows version 7.4.8 or above


OpenCVE Recommended Actions

  • Upgrade FortiClientWindows to version 7.4.8 or any 8.0.0 release or higher to apply the vendor fix for the access control flaw
  • Confirm that 7.4.8+ deployments have proper ownership verification enabled by reviewing client configuration settings
  • Apply network segmentation or access-limiting controls to reduce the attack surface until the client upgrade is completed

Generated by OpenCVE AI on September 8, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unverified Ownership Access Control Vulnerability in FortiClientWindows

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>
First Time appeared Fortinet
Fortinet forticlientwindows
Weaknesses CWE-283
CPEs cpe:2.3:a:fortinet:forticlientwindows:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.15:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlientwindows:7.4.7:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet forticlientwindows
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Forticlientwindows
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-09-08T17:42:36.815Z

Reserved: 2026-09-01T16:36:06.039Z

Link: CVE-2026-84386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:18:37.173

Modified: 2026-09-08T18:35:10.323

Link: CVE-2026-84386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:12Z

Weaknesses