CVE-2026-21741: Medium severity Fortinet FortiNAC-F vulnerability
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21741?
CVE-2026-21741 has a high severity rating due to its potential to allow remote attackers to redirect users to malicious sites.
How do I fix CVE-2026-21741?
To fix CVE-2026-21741, upgrade to Fortinet FortiNAC-F versions 7.6.6 or later by applying the latest patches provided by Fortinet.
Who is affected by CVE-2026-21741?
CVE-2026-21741 affects Fortinet FortiNAC-F versions 7.6.0 to 7.6.5, 7.4 (all versions), and 7.2 (all versions).
What type of vulnerability is CVE-2026-21741?
CVE-2026-21741 is classified as an Open Redirect vulnerability, allowing redirection to untrusted sites.
Can CVE-2026-21741 be exploited remotely?
Yes, CVE-2026-21741 can be exploited remotely by an attacker with system administrator privileges.