CVE-2026-84391: Medium severity Fortinet FortiAnalyzer vulnerability
A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiAnalyzerto a version that resolves this vulnerability.Fixed in 7.6.7 - Upgrade
Upgrade
Fortinet FortiAnalyzerto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low privileges (PR:L) and can exploit the issue remotely over the network (AV:N). No user interaction is required (UI:N).
Which FortiAnalyzer versions are affected?
FortiAnalyzer versions 7.6.3 through 7.6.6 are identified as affected.
What is the expected impact of a successful exploit?
The stated impact is denial of service. The CVSS vector indicates high availability impact (A:H), with no confidentiality or integrity impact (C:N/I:N).