CVE-2026-84392: Null Pointer Dereference
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.0 - Upgrade
Upgrade
Fortinet FortiPAMto a version that resolves this vulnerability.Fixed in 1.9.1 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.7
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and have high privileges. Exploitation is performed remotely by sending crafted HTTP requests.
What is the expected security impact of successful exploitation?
Successful exploitation can crash the httpsd daemon, causing an availability impact. The provided scoring indicates no confidentiality or integrity impact.
Which product releases are in scope?
Affected releases include all FortiOS 7.4 and 7.2 versions; FortiPAM 1.9.0 and all versions from 1.0 through 1.8; FortiProxy 7.6.0 through 7.6.6; and all FortiProxy 7.4 and 7.2 versions.