Junglewise Threat Intelligence

CVE-2026-84392: Fortinet FortiOS, FortiProxy, FortiPAM NULL pointer dereference in httpsd

CVE-2026-84392 · Severity: low · CVSS 2.7 · Published 2026-09-08

Technologies: Fortinet Fortipam, Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A NULL pointer dereference vulnerability in the web administration daemon (httpsd) of Fortinet's FortiOS, FortiProxy, and FortiPAM products allows an authenticated attacker to crash the service via malformed HTTP requests. This causes temporary unavailability of the device's web interface and management functions until the service recovers, disrupting administrative access and visibility into security operations.

Technical details

A NULL pointer dereference (CWE-476) exists in the httpsd daemon's HTTP request handling logic, specifically triggered by crafted HTTP requests in the log report summary component. The vulnerability requires prior authentication to the web interface. An authenticated attacker can send specially crafted HTTP requests that cause a NULL pointer to be dereferenced, crashing the httpsd daemon and causing denial of service. Patches are available: FortiOS 7.4 and 7.2 require migration to fixed versions; FortiPAM 1.9.0 is fixed in 1.9.1 or above; FortiProxy 7.6.0–7.6.6 is fixed in 7.6.7 or above; other FortiPAM and FortiProxy versions require migration to fixed releases.

Affected products

  • Fortinet FortiOS 7.2 all versions, 7.4 all versions
  • Fortinet FortiPAM 1.0 all versions through 1.8 all versions, 1.9.0
  • Fortinet FortiProxy 7.2 all versions, 7.4 all versions, 7.6.0 through 7.6.6

Timeline

  • 2026-09-08: disclosed

References

Related threats