CVE-2026-59841
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert atta
Severity
Medium 6.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Jul 14, 2026
Assigned by fortinet
Description
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
Weakness: CWE-923
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSIEMWindowsAgent
Credit
Fortinet is pleased to thank Nicola Scremin (@ScreSys) for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiSIEMWindowsAgent version 7.4.2 or above