Sceawere

Vulnerability Detail

CVE-2026-84390UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FortiMonitorOnSight Sensitive Information Inclusion

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Fortinet
Product
FortiMonitorOnSight
Attack Type
Improper access control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-11T13:18:18.980Z",
  "pubdate": "2026-09-11T13:18:18.980Z",
  "executiveSummary": "This vulnerability is classified as an Inclusion of Sensitive Information in Source Code, which poses a significant risk to the security integrity of the FortiMonitorOnSight appliance.\nThe vulnerability affects versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7. It stems from the unintentional exposure of sensitive credentials, keys, or internal configuration data within the application's source code or associated static files.\nSuch exposure provides unauthorized attackers with the capability to harvest critical information that may lead to escalated privileges, lateral movement within the network, or further system compromise.\nThe risk implication is critical, as it bypasses standard access control mechanisms, potentially exposing authentication secrets that would otherwise require high-level administrative access to retrieve.\nAn attacker does not necessarily require complex exploit chains if the sensitive data is directly accessible, meaning that any actor with network visibility to the exposed source or configuration files can leverage this flaw.\nThe exploitation requirement is limited to the ability of the attacker to access the specific files where the sensitive information is stored, which is facilitated by the improper control mechanisms in the affected software versions.",
  "technicalDetails": "The root cause of this vulnerability is the poor management of sensitive configuration parameters, hardcoded credentials, or internal API tokens that have been inadvertently committed or left in the source code of the FortiMonitorOnSight application.\nWithin the context of the affected versions (7.2.0-7.2.2 and 7.2.4-7.2.7), the application logic fails to sanitize or protect sensitive data, resulting in its inclusion within files that may be accessible via the application server's file system or through web-accessible directories.\nThe exploitation process typically follows a multi-stage attack flow. First, an attacker performs reconnaissance to identify accessible endpoints or directories that may inadvertently serve static files, including source files or backup configuration manifests.\nOnce these files are retrieved, the attacker parses the content to extract embedded secrets, such as database credentials, cryptographic salts, SSH keys, or administrative authentication tokens.\nWith these secrets in hand, the attacker can move to the exploitation phase, which involves using the harvested credentials to authenticate to backend services, internal databases, or administrative interfaces that were intended to be restricted.\nBecause these secrets are often hardcoded for development or debugging purposes, they frequently carry elevated privileges that allow the attacker to manipulate the appliance configuration, exfiltrate monitored data, or modify system logs to hide their tracks.\nThe vulnerability is exacerbated by the lack of robust access control during the software deployment lifecycle. Since the sensitive information is effectively 'baked in' to the software image, the security of the entire instance is compromised as soon as the deployment is accessed by an unauthorized party.\nThe post-exploitation impact includes full system compromise, the potential for unauthorized data access across the monitored infrastructure, and the ability to execute further malicious commands with the privileges associated with the exposed credentials.\nThis issue highlights a failure in the secure development lifecycle, specifically regarding secret management practices and static analysis testing which should have flagged these artifacts before the release of the 7.2.x firmware builds."
}
CVE-2026-84390: FortiMonitorOnSight Sensitive Information Inclusion (CRITICAL Severity, CVSS: 9.8) | Sceawere