Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-84386

CVE-2026-84386: FortiClient Windows Auth Bypass Vulnerability

CVE-2026-84386 is an authentication bypass flaw in Fortinet FortiClient Windows versions 7.2 and 7.4.0-7.4.7 that enables improper access control. This article covers the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-84386 Overview

CVE-2026-84386 is an unverified ownership vulnerability [CWE-283] affecting Fortinet FortiClient for Windows. The flaw impacts FortiClientWindows versions 7.4.0 through 7.4.7 and all versions of FortiClientWindows 7.2. An authenticated local attacker can leverage improper access control to affect the confidentiality, integrity, or availability of the endpoint agent.

The issue stems from the software failing to verify that an actor accessing a resource is the legitimate owner. This weakness can allow a local, privileged user to manipulate resources belonging to the FortiClient process. Fortinet documented the issue in advisory FG-IR-26-165.

Critical Impact

A local attacker with high privileges can abuse unverified ownership checks in FortiClient for Windows to tamper with agent resources, potentially disrupting endpoint protection availability.

Affected Products

  • Fortinet FortiClientWindows 7.4.0 through 7.4.7
  • Fortinet FortiClientWindows 7.2 (all versions)
  • Windows endpoints running vulnerable FortiClient installations

Discovery Timeline

  • 2026-09-08 - CVE-2026-84386 published to NVD
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-84386

Vulnerability Analysis

The vulnerability is classified under CWE-283: Unverified Ownership. FortiClient for Windows performs an action on a resource without confirming that the requesting actor owns or is authorized to modify that resource. On a shared or multi-user Windows host, this gap in ownership validation lets a local actor influence resources associated with the FortiClient agent.

Exploitation requires local access and high privileges, and no user interaction is needed. The impact is scoped to the endpoint itself, with the primary consequences being loss of integrity and loss of availability of the FortiClient service. Confidentiality of user data is not directly impacted based on the vector.

Root Cause

The root cause is missing ownership verification before FortiClient acts on a resource. When the software processes a request to interact with a file, handle, or registry object, it does not confirm the caller owns the target. An attacker who already holds elevated privileges on the host can exploit this trust gap to redirect operations against resources they do not legitimately control.

Attack Vector

The attack vector is local. An authenticated user with high privileges on the Windows host interacts with FortiClient in a way that triggers an operation on a resource the attacker does not own. Because FortiClient does not validate ownership, the operation succeeds and the attacker can influence agent behavior or resource state. Refer to the Fortinet Security Advisory FG-IR-26-165 for vendor-specific technical details.

No public proof-of-concept exploit was available at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-84386

Indicators of Compromise

  • Unexpected modification, replacement, or deletion of files under the FortiClient installation directory by non-SYSTEM accounts.
  • Unexplained stops, restarts, or crashes of FortiClient services (FA_Scheduler, FortiESNAC, FortiSSLVPNdaemon).
  • Registry changes to FortiClient keys performed by local user accounts rather than the FortiClient installer or service.

Detection Strategies

  • Monitor Windows Security and Sysmon event logs for file and handle operations against FortiClient resources originating from non-service principals.
  • Alert on privilege escalation patterns preceding interaction with FortiClient binaries or configuration files.
  • Correlate FortiClient service state changes with the identity of the initiating process to identify unauthorized manipulation.

Monitoring Recommendations

  • Enable Sysmon Event IDs 1, 7, 11, and 13 to capture process creation, image loads, file writes, and registry modifications tied to FortiClient paths.
  • Baseline normal FortiClient update and agent-service behavior so ownership-related anomalies stand out.
  • Forward endpoint telemetry to a centralized analytics platform for cross-host correlation of local privilege abuse patterns.

How to Mitigate CVE-2026-84386

Immediate Actions Required

  • Inventory Windows endpoints running FortiClient 7.4.0 through 7.4.7 or any 7.2.x release and prioritize remediation.
  • Restrict local administrator rights on Windows endpoints to reduce the pool of accounts capable of exploiting this local vector.
  • Review the Fortinet Security Advisory FG-IR-26-165 and align remediation with the vendor's fixed release guidance.

Patch Information

Fortinet has published advisory FG-IR-26-165 covering CVE-2026-84386. Administrators should upgrade FortiClientWindows to a fixed release identified in the advisory. Because FortiClientWindows 7.2 is affected across all versions, migrating to a patched 7.4.x build listed by Fortinet is the recommended path.

Workarounds

  • Enforce least privilege so standard users cannot obtain the high privileges required to trigger the flaw.
  • Apply application control policies to prevent unauthorized processes from interacting with FortiClient files and registry keys.
  • Use endpoint tamper protection features to block modification of security agent components by non-authorized actors.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.