CVE-2026-84389 PUBLISHED

Assigner: fortinet
Reserved: 01.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CVSS Score: 2.8

Product Status

Vendor Fortinet
Product FortiSIEM
Versions Default: unaffected
  • affected from 7.5.0 to 7.5.1 (incl.)
  • affected from 7.4.1 to 7.4.2 (incl.)

Solutions

Upgrade to upcoming FortiSIEM version 7.6.0 or above Upgrade to upcoming FortiSIEM version 7.5.2 or above

References

Problem Types

  • Execute unauthorized code or commands CWE