CVE-2026-84392:
FortiOS 취약성 분석 및 완화
개요
CVE-2026-84392 is a NULL Pointer Dereference vulnerability (CWE-476) affecting Fortinet FortiOS, FortiProxy, and FortiPAM that allows an authenticated attacker to crash the httpsd daemon via crafted HTTP requests, resulting in a denial of service. It was disclosed on September 8, 2026, with Fortinet publishing advisory FG-IR-26-173. Affected versions include FortiOS 7.2 and 7.4 (all versions), FortiProxy 7.2, 7.4, and 7.6.0–7.6.6, and FortiPAM 1.0 through 1.9.0. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) per NVD, and 2.5 (Low) per Fortinet's own scoring (Fortinet PSIRT).
기술적 세부 사항
The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the GUI component (httpsd daemon) of the affected Fortinet products. An authenticated attacker can send specially crafted HTTP requests to the management interface, triggering a null pointer dereference that causes the httpsd process to crash. Exploitation requires valid credentials (high privileges), making it a post-authentication issue with no known public proof-of-concept code at the time of disclosure. The vulnerability was discovered externally and reported by Vang3lis and Cyth from VARAS@IIE under responsible disclosure (Fortinet PSIRT).
영향
Successful exploitation results in a denial of service by crashing the httpsd daemon, which handles the web-based management GUI of affected Fortinet products. This would disrupt administrative access to the device but does not result in unauthorized code execution, data exfiltration, or privilege escalation, as confidentiality and integrity impacts are rated None. The scope is limited to the affected device's management plane, with no evidence of lateral movement potential (Fortinet PSIRT).
악용 가능성
No public proof-of-concept exploit code has been identified, and Fortinet confirms the vulnerability has not been exploited in the wild (Known Exploited: No). The EPSS score is approximately 0.0028 (0.28%), reflecting a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Fortinet PSIRT).
완화 및 해결 방법
Fortinet recommends upgrading to fixed versions as follows: FortiPAM 1.9.1 or above (for 1.9.0 users); FortiProxy 7.6.7 or above (for 7.6.0–7.6.6 users). Users running FortiOS 7.2 or 7.4, FortiProxy 7.2 or 7.4, or FortiPAM 1.0–1.8 should migrate to a fixed release, as no in-branch patch is available for those versions. FortiOS 7.6 and 8.0 are not affected. Fortinet's upgrade path tool at https://docs.fortinet.com/upgrade-tool can assist with planning the migration (Fortinet PSIRT).
커뮤니티 반응
Coverage of CVE-2026-84392 has been limited given its low severity rating. The vulnerability was noted in aggregator feeds such as VulDB and CVEFeed.io shortly after disclosure, and BeyondMachines included it in a broader roundup of Fortinet patches addressing authentication bypass and proxy flaws across the product line. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking (Fortinet PSIRT).
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 FortiOS 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."