CVE-2026-21741
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may al
Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet
Description
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
Weakness: CWE-601
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiNAC | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiNAC-F
Credit
Discovered during an independent audit commissioned by Fortinet.
Vendor remediation
Upgrade to upcoming FortiNAC-F version 7.6.6 or above