Vulnerability
Published 2026-09-09
Verified 2026-09-19

Fortinet: FortiMonitorOnSight JWT auth bypass CVE-2026-84390 (9.6); Chrome PA agent CVE-2026-84388 (9.1)

SecurityWeek (9 September 2026) summarises Fortinet's Tuesday patch set of ten vulnerabilities. Critical CVE-2026-84390 (CVSS 9.6) is inclusion of sensitive information in source code on the FortiMonitorOnSight web portal — a remote unauthenticated attacker can bypass authentication via a forged or reused JWT. Critical CVE-2026-84388 (CVSS 9.1) is improper authentication in the Fortinet Privileged Access Agent Chrome extension — a remote unauthenticated attacker can proxy a victim's browser traffic if the user visits a malicious site. Fortinet says full remediation needs FortiPAM 1.9.1 or 1.8.4 plus Chrome extension 8.0.1.123 or newer. Same batch includes high issues in FortiSandbox (CVE-2026-26084) and FortiOS/FortiProxy. Primary wire: SecurityWeek; confirm builds on FortiGuard PSIRT.

Product
FortiMonitorOnSight; Fortinet Privileged Access Agent Chrome extension; FortiPAM; FortiSandbox; FortiOS/FortiProxy
Versions
FortiPAM 1.9.1 or 1.8.4; Chrome extension ≥8.0.1.123; see FortiGuard PSIRT for FortiMonitorOnSight and other fixed builds
CVSS
CVE-2026-84390 9.6; CVE-2026-84388 9.1 (SecurityWeek citing Fortinet)
Exploited in Australia?
unknown
Patch to
Upgrade FortiMonitorOnSight per PSIRT; FortiPAM 1.9.1/1.8.4 and Chrome PA agent ≥8.0.1.123 together; apply FortiSandbox/FortiOS/FortiProxy highs

Primary: SecurityWeek — Fortinet criticals (9 Sep 2026) · Vendor: FortiGuard PSIRT index · CVE: CVE-2026-84390, CVE-2026-84388, CVE-2026-26084

vulnerabilities network identity cloud