Fortinet: FortiMonitorOnSight JWT auth bypass CVE-2026-84390 (9.6); Chrome PA agent CVE-2026-84388 (9.1)
SecurityWeek (9 September 2026) summarises Fortinet's Tuesday patch set of ten vulnerabilities. Critical CVE-2026-84390 (CVSS 9.6) is inclusion of sensitive information in source code on the FortiMonitorOnSight web portal — a remote unauthenticated attacker can bypass authentication via a forged or reused JWT. Critical CVE-2026-84388 (CVSS 9.1) is improper authentication in the Fortinet Privileged Access Agent Chrome extension — a remote unauthenticated attacker can proxy a victim's browser traffic if the user visits a malicious site. Fortinet says full remediation needs FortiPAM 1.9.1 or 1.8.4 plus Chrome extension 8.0.1.123 or newer. Same batch includes high issues in FortiSandbox (CVE-2026-26084) and FortiOS/FortiProxy. Primary wire: SecurityWeek; confirm builds on FortiGuard PSIRT.
- Product
- FortiMonitorOnSight; Fortinet Privileged Access Agent Chrome extension; FortiPAM; FortiSandbox; FortiOS/FortiProxy
- Versions
- FortiPAM 1.9.1 or 1.8.4; Chrome extension ≥8.0.1.123; see FortiGuard PSIRT for FortiMonitorOnSight and other fixed builds
- CVSS
- CVE-2026-84390 9.6; CVE-2026-84388 9.1 (SecurityWeek citing Fortinet)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade FortiMonitorOnSight per PSIRT; FortiPAM 1.9.1/1.8.4 and Chrome PA agent ≥8.0.1.123 together; apply FortiSandbox/FortiOS/FortiProxy highs
Primary: SecurityWeek — Fortinet criticals (9 Sep 2026) · Vendor: FortiGuard PSIRT index · CVE: CVE-2026-84390, CVE-2026-84388, CVE-2026-26084
