Description
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
Published: 2026-07-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper restriction of communication channel to intended endpoints in Fortinet FortiSIEM Windows Agent 7.4.0 through 7.4.1 allows a malicious actor to potentially obtain higher privileges on the host. The weakness is classified as CWE‑923, indicating that the agent fails to enforce secure communication boundaries, which could enable exploitation of the privileged privilege chain. The advisory notes that an escalation of privilege may be possible but does not provide a concrete attack vector, so the exact path of exploitation remains unspecified.

Affected Systems

Fortinet FortiSIEM Windows Agent versions 7.4.0 and 7.4.1 are affected. Users running these versions are at risk and should consider upgrading to 7.4.2 or later, where the flaw is fixed.

Risk and Exploitability

The CVSS score of 6.9 denotes a moderate risk. The EPSS score is below 1%, indicating that observed exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Because the advisory does not specify the attack vector, whether the issue can be exploited remotely or only locally is uncertain, but any exploitation would grant elevated privileges, justifying caution.

Generated by OpenCVE AI on August 1, 2026 at 09:58 UTC.

Remediation

Vendor Solution

Upgrade to FortiSIEMWindowsAgent version 7.4.2 or above


OpenCVE Recommended Actions

  • Upgrade FortiSIEM Windows Agent to version 7.4.2 or newer.
  • Restrict inbound and outbound traffic from the agent so that it can communicate only with authenticated FortiSIEM servers.
  • Review security logs for signs of privilege elevation or anomalous agent connections.

Generated by OpenCVE AI on August 1, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Channel Restriction in FortiSIEM Windows Agent

Wed, 29 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Channel Restriction in FortiSIEM Windows Agent

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Endpoint Communication Restrictions in FortiSIEM Windows Agent

Thu, 23 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Endpoint Communication Restrictions in FortiSIEM Windows Agent

Fri, 17 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Communication Channel Leading to Privilege Escalation in FortiSIEM Windows Agent

Thu, 16 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Communication Channel Leading to Privilege Escalation in FortiSIEM Windows Agent

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortisiemwindowsagent
Weaknesses CWE-923
CPEs cpe:2.3:a:fortinet:fortisiemwindowsagent:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiemwindowsagent:7.4.1:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisiemwindowsagent
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortisiemwindowsagent
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-15T03:59:10.652Z

Reserved: 2026-07-07T15:21:38.323Z

Link: CVE-2026-59841

cve-icon Vulnrichment

Updated: 2026-07-14T15:50:37.061Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints