CVE-2026-70467

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, Fo

Severity
Low 3.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
17.6th percentile
Discovered by
Third party
Vendor advisory field
Published
Aug 12, 2026
Assigned by fortinet

Description

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Weakness: CWE-918

Affected products

Vendor Product Category Matched by
Fortinet FortiSIEM SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSIEM

Credit

Discovered and Responsibly reported by external researcher khalooda0x - Khaled ibn Al-Walid.

Vendor remediation

Upgrade to FortiSIEM version 7.5.1 or above Upgrade to upcoming FortiSIEM version 7.4.3 or above Upgrade to upcoming FortiSIEM version 7.3.6 or above

Something wrong here?