CVE-2026-84390
FortiMonitorOnSight JWT authentication bypass allows unauthenticated web portal access (CVE-2026-84390)
Fortinet FortiMonitorOnSight web portal has a critical JWT authentication bypass (CVE-2026-84390) in versions 7.2.0–7.2.2 and 7.2.4–7.2.7. No fixed version or workaround is listed; restrict network exposure and monitor access.
What happened
Fortinet's advisory describes a CWE-540 inclusion of sensitive information in source code in the FortiMonitorOnSight web portal: the JWT used for portal authentication is signed with a static key. Fortinet says a remote unauthenticated attacker may bypass authentication by forging or reusing that JWT.
The CVSS 3.1 score is 9.6 (critical): the attack is network-based, low complexity, requires no privileges and no user interaction, and can lead to high impact on confidentiality, integrity and availability. The CVE record lists no exploitation and no public disclosure, and it is not in CISA's KEV catalogue. Fortinet has not published a fixed version or a workaround.
Who is affected
This affects FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. The vulnerable component is the web portal. Organisations that expose the portal beyond a trusted management network have the greatest immediate exposure, because the flaw is reachable over the network without credentials. Versions outside these ranges are not addressed by this advisory.
What to do now
- Identify FortiMonitorOnSight deployments and confirm whether they run 7.2.0 through 7.2.2 or 7.2.4 through 7.2.7.
- Restrict access to the FortiMonitorOnSight web portal. No patch or workaround is listed by Fortinet, so remove the portal from internet exposure or place it behind a trusted management network with strict access controls.
- Review access to the portal for successful sessions that cannot be accounted for, particularly from unexpected addresses.
- Monitor Fortinet advisory FG-IR-26-170 for updated fixing information and re-check this page when a fixed version is available.
How to detect it
The FortiMonitorOnSight web portal is the named attack surface. If it is reachable from the internet, treat successful portal sessions from unexpected IP addresses or at unusual times as suspicious. Fortinet has not published specific indicators of compromise for this CVE.
Beyond the patch
This is a pre-authentication flaw in vendor-supplied software that is easy to leave exposed until an advisory makes it urgent. Because the issue is network-reachable without credentials, Virtual CISO Services (vCISO) can help you find exposed FortiMonitorOnSight portals before the next bulletin, and Supply Chain Defense & Third-Party Risk can put Fortinet product tracking into your third-party risk routine.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| FortiMonitorOnSight | 7.2.4 – ≤ 7.2.7 7.2.0 – ≤ 7.2.2 | No fixed version listed yet |