CVE-2026-25972: XSS
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering attack via spoofed URL parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25972?
CVE-2026-25972 is categorized with a medium severity rating due to its potential to facilitate social engineering attacks.
How do I fix CVE-2026-25972?
To fix CVE-2026-25972, upgrade Fortinet FortiSIEM to version 7.4.1 or higher immediately.
Who is affected by CVE-2026-25972?
CVE-2026-25972 affects Fortinet FortiSIEM versions 7.3.0 to 7.3.4 and version 7.4.0.
What type of vulnerability is CVE-2026-25972?
CVE-2026-25972 is an improper neutralization of input during web page generation, commonly known as a cross-site scripting (XSS) vulnerability.
Can CVE-2026-25972 be exploited remotely?
Yes, CVE-2026-25972 can be exploited by a remote unauthenticated attacker, enabling them to conduct social engineering attacks.