Skip to content

CVE-2026-84390

FortiMonitorOnSight JWT authentication bypass allows unauthenticated web portal access (CVE-2026-84390)

Critical 9.6 Vendor: Fortinet Published

Fortinet FortiMonitorOnSight web portal has a critical JWT authentication bypass (CVE-2026-84390) in versions 7.2.0–7.2.2 and 7.2.4–7.2.7. No fixed version or workaround is listed; restrict network exposure and monitor access.

What happened

Fortinet's advisory describes a CWE-540 inclusion of sensitive information in source code in the FortiMonitorOnSight web portal: the JWT used for portal authentication is signed with a static key. Fortinet says a remote unauthenticated attacker may bypass authentication by forging or reusing that JWT.

The CVSS 3.1 score is 9.6 (critical): the attack is network-based, low complexity, requires no privileges and no user interaction, and can lead to high impact on confidentiality, integrity and availability. The CVE record lists no exploitation and no public disclosure, and it is not in CISA's KEV catalogue. Fortinet has not published a fixed version or a workaround.

Who is affected

This affects FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. The vulnerable component is the web portal. Organisations that expose the portal beyond a trusted management network have the greatest immediate exposure, because the flaw is reachable over the network without credentials. Versions outside these ranges are not addressed by this advisory.

What to do now

  1. Identify FortiMonitorOnSight deployments and confirm whether they run 7.2.0 through 7.2.2 or 7.2.4 through 7.2.7.
  2. Restrict access to the FortiMonitorOnSight web portal. No patch or workaround is listed by Fortinet, so remove the portal from internet exposure or place it behind a trusted management network with strict access controls.
  3. Review access to the portal for successful sessions that cannot be accounted for, particularly from unexpected addresses.
  4. Monitor Fortinet advisory FG-IR-26-170 for updated fixing information and re-check this page when a fixed version is available.

How to detect it

The FortiMonitorOnSight web portal is the named attack surface. If it is reachable from the internet, treat successful portal sessions from unexpected IP addresses or at unusual times as suspicious. Fortinet has not published specific indicators of compromise for this CVE.

Beyond the patch

This is a pre-authentication flaw in vendor-supplied software that is easy to leave exposed until an advisory makes it urgent. Because the issue is network-reachable without credentials, Virtual CISO Services (vCISO) can help you find exposed FortiMonitorOnSight portals before the next bulletin, and Supply Chain Defense & Third-Party Risk can put Fortinet product tracking into your third-party risk routine.

Affected and fixed versions

ProductAffectedFixed in
FortiMonitorOnSight7.2.4 – ≤ 7.2.7
7.2.0 – ≤ 7.2.2
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.