CVE-2026-84389: Low severity Fortinet FortiSIEM vulnerability
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.5.2 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Frequently Asked Questions
Which FortiSIEM releases are affected?
The affected releases are FortiSIEM 7.5.0 through 7.5.1 and FortiSIEM 7.4.1 through 7.4.2.
Does exploitation require an authenticated account?
No. The supplied CVSS vector indicates that no privileges are required, although exploitation requires user interaction and has high attack complexity.
What security impact is indicated?
The supplied severity data indicates integrity impact only, with no indicated confidentiality or availability impact. The description states that the issue may allow unauthorized code or command execution through the unspecified attack vector.