CVE-2026-84389

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands

Severity
Low 2.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
3.4th percentile
Discovered by
Third party
Vendor advisory acknowledgement
Published
Sep 8, 2026
Assigned by fortinet

Description

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Weakness: CWE-601

Affected products

Vendor Product Category Matched by
Fortinet FortiSIEM SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSIEM

Credit

Fortinet is pleased to thank khalooda0x - Khaled ibn Al-Walid for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to upcoming FortiSIEM version 7.6.0 or above Upgrade to upcoming FortiSIEM version 7.5.2 or above

Something wrong here?