CVE-2026-21741

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may al

Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet

Description

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.

Weakness: CWE-601

Affected products

Vendor Product Category Matched by
Fortinet FortiNAC Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiNAC-F

Credit

Discovered during an independent audit commissioned by Fortinet.

Vendor remediation

Upgrade to upcoming FortiNAC-F version 7.6.6 or above

Something wrong here?