Junglewise Threat Intelligence

CVE-2026-84390: Fortinet FortiMonitorOnSight authentication bypass via static JWT key

CVE-2026-84390 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Vendors: Fortinet.

Executive brief

FortiMonitorOnSight is a Fortinet monitoring and alerting platform used by organizations to manage security infrastructure. A vulnerability in the web GUI allows unauthenticated remote attackers to forge or reuse authentication tokens, bypassing login controls and gaining unauthorized access to the entire monitoring platform.

Technical details

The vulnerability (CWE-540: Inclusion of Sensitive Information in Source Code) stems from JWT tokens used for authentication in the web GUI being signed with a static key rather than a unique, secrets-managed key. An unauthenticated attacker on the network can forge or reuse valid JWTs to impersonate legitimate users and bypass authentication controls. This requires network access to the web GUI but no credentials or user interaction. An attacker can achieve complete unauthorized access to the monitoring platform and potentially the systems it monitors. Patches are available: FortiMonitorOnSight 7.2.0–7.2.2 and 7.2.4–7.2.7 should upgrade to 7.2.8 or above.

Affected products

  • Fortinet FortiMonitorOnSight 7.2.0 through 7.2.2, 7.2.4 through 7.2.7

Timeline

  • 2026-09-08: disclosed
  • 2026-09-11: advisory

References