CVE-2026-84389
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands
Severity
Low 2.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
3.4th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet
Description
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Weakness: CWE-601
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSIEM
Credit
Fortinet is pleased to thank khalooda0x - Khaled ibn Al-Walid for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to upcoming FortiSIEM version 7.6.0 or above Upgrade to upcoming FortiSIEM version 7.5.2 or above