CVE-2026-23573

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS

Severity
Medium 6.1
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.3th percentile
Discovered by
Not disclosed
Published
Jul 14, 2026
Assigned by fortinet

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Fortinet · FortiOS
  • Fortinet · FortiProxy
  • Fortinet · FortiPAM

Vendor remediation

Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to FortiProxy version 7.4.4 or above Upgrade to FortiProxy version 7.2.10 or above Upgrade to FortiProxy version 7.0.17 or above Upgrade to FortiPAM version 1.9.0 or above Upgrade to FortiPAM version 1.8.1 or above Fortinet remediated this issue in FortiSASE version 26.1.1 and hence customers do not need to perform any action. Upgrade to FortiSwitchManager version 7.2.5 or above Upgrade to FortiSwitchManager version 7.0.3 or above