Skip to main content
Vulnerability Database/CVE-2026-84385

CVE-2026-84385: FortiSOAR Privilege Escalation Vulnerability

CVE-2026-84385 is a privilege escalation vulnerability in Fortinet FortiSOAR affecting versions 7.3 through 7.6.6. This improper access control flaw enables attackers to elevate privileges. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-84385 Overview

CVE-2026-84385 is an improper access control vulnerability [CWE-284] affecting multiple versions of Fortinet FortiSOAR, including both Platform-as-a-Service (PaaS) and on-premise deployments. An authenticated attacker with low privileges can exploit the flaw to escalate privileges within the FortiSOAR environment. The vulnerability impacts FortiSOAR 7.3, 7.4, 7.5.0 through 7.5.3, and 7.6.0 through 7.6.6 across both deployment models. Fortinet published the issue in advisory FG-IR-26-164.

Critical Impact

Authenticated low-privilege users can escalate privileges within FortiSOAR, gaining unauthorized access to playbooks, integrations, and sensitive orchestration data.

Affected Products

  • Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, 7.5.0 through 7.5.3, and all versions of 7.4 and 7.3
  • Fortinet FortiSOAR on-premise 7.6.0 through 7.6.6, 7.5.0 through 7.5.3, and all versions of 7.4 and 7.3
  • Both cloud-hosted and self-managed FortiSOAR deployments

Discovery Timeline

  • 2026-09-08 - CVE CVE-2026-84385 published to the National Vulnerability Database
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-84385

Vulnerability Analysis

The vulnerability resides in the access control logic of FortiSOAR, Fortinet's Security Orchestration, Automation, and Response (SOAR) platform. FortiSOAR enforces role-based access control (RBAC) to restrict actions such as playbook execution, integration management, and administrative operations. The flaw allows an authenticated user with limited permissions to perform actions outside their assigned role. Successful exploitation grants elevated privileges within the platform, enabling access to sensitive orchestration assets. Because FortiSOAR aggregates credentials, playbooks, and connectors for downstream security tools, unauthorized privilege escalation can cascade across the broader security operations environment.

Root Cause

The root cause is improper access control [CWE-284] within FortiSOAR's authorization layer. The platform fails to consistently validate that the requesting user holds the privileges required for a given action. Fortinet's advisory FG-IR-26-164 confirms the weakness across all supported release trains from 7.3 through 7.6.6. Fortinet has not published detailed technical mechanics of the flaw in public references.

Attack Vector

The attack requires network access to the FortiSOAR web interface or API and valid low-privilege credentials. User interaction is not required. An attacker authenticated as a standard user can issue crafted requests that bypass authorization checks to perform privileged actions. The exploit's confidentiality and integrity impact are limited, while availability is unaffected. Refer to the Fortinet Security Advisory FG-IR-26-164 for vendor guidance.

// No verified public proof-of-concept code is available.
// See the Fortinet advisory for technical details and fixed versions.

Detection Methods for CVE-2026-84385

Indicators of Compromise

  • Unexpected role changes, permission grants, or team membership modifications in FortiSOAR audit logs
  • API requests from low-privilege user accounts targeting administrative endpoints under /api/auth/ or /api/rbac/
  • Playbook or connector modifications performed by accounts that historically lack such permissions
  • Newly created appliance or service accounts without corresponding change management records

Detection Strategies

  • Baseline normal user activity per role and alert on deviations, particularly API calls to privileged endpoints from non-admin users
  • Correlate FortiSOAR audit events with authentication logs to identify anomalous privilege usage after login
  • Monitor for playbook executions initiated by users whose assigned roles do not include automation privileges

Monitoring Recommendations

  • Forward FortiSOAR audit and application logs to a centralized SIEM for retention and correlation
  • Enable alerting on user role escalation events, API errors returning 403 followed by 200 on the same endpoint, and mass configuration changes
  • Review integration and connector credential access logs for reads by unexpected accounts

How to Mitigate CVE-2026-84385

Immediate Actions Required

  • Upgrade FortiSOAR on-premise deployments to a fixed version per the Fortinet Security Advisory FG-IR-26-164
  • Confirm that FortiSOAR PaaS tenants have received the vendor-managed patch, as Fortinet operates PaaS remediation
  • Audit all FortiSOAR user accounts, roles, and team memberships for unauthorized changes
  • Rotate credentials, API keys, and integration secrets stored within FortiSOAR if compromise is suspected

Patch Information

Fortinet has released updated FortiSOAR builds addressing CVE-2026-84385. Refer to Fortinet Security Advisory FG-IR-26-164 for the specific fixed versions across the 7.3, 7.4, 7.5, and 7.6 release trains. FortiSOAR PaaS customers receive patches through Fortinet's managed update process.

Workarounds

  • Restrict network access to the FortiSOAR management interface to trusted administrative networks and jump hosts
  • Enforce multi-factor authentication (MFA) for all FortiSOAR users to reduce the risk of credential-based abuse
  • Apply the principle of least privilege by removing unnecessary user accounts and tightening role assignments until patching is complete
bash
# Example: restrict FortiSOAR web access at the network layer
# Replace 10.0.0.0/24 with your administrative subnet
iptables -A INPUT -p tcp --dport 443 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.