CVE-2026-23573: SSL-VPN Reflected XSS
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests.
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.7 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.8.1 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.9.0 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.17 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.10 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.3 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23573?
The severity of CVE-2026-23573 is rated as medium with a score of 6.1.
What type of vulnerability is CVE-2026-23573?
CVE-2026-23573 is a reflected cross-site scripting (XSS) vulnerability.
How can CVE-2026-23573 be exploited?
CVE-2026-23573 can be exploited by an authenticated remote user executing code via crafted requests.
What software is affected by CVE-2026-23573?
CVE-2026-23573 affects Fortinet FortiOS, FortiProxy, FortiPAM, and FortiSwitch-Manager Agentless SSL-VPN.
What mitigation steps can be taken for CVE-2026-23573?
Mitigation for CVE-2026-23573 involves applying the latest security updates from Fortinet.