Description
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Published: 2026-08-12
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (SSRF) that allows an attacker to direct the FortiSIEM server to send arbitrary requests. Accordingly, this could lead to the execution of unauthorized code or commands if the attacker can reach internal or external services. The flaw is identified as CWE‑918, indicating that the server does not properly validate user‑controlled URLs or payloads. Impact is restricted to the FortiSIEM appliance – the attacker must be able to submit a malicious request to a vulnerable component, typically through the web interface or API. Inferred from the description, the threat requires network access to the FortiSIEM appliance and exploitation of an SSRF‑capable endpoint.

Affected Systems

Affected systems include Fortinet FortiSIEM releases: 7.5.0, 7.4.0 through 7.4.2, 7.3.0 through 7.3.5, all 7.2.x, all 7.1.x, all 7.0.x, all 6.7.x, all 6.6.x, and all 6.5.x server‑side request forgery vulnerable API components. FortiSIEM versions 7.5.1 and later, 7.4.3 and later, and 7.3.6 and later include the fix, so these are not affected.

Risk and Exploitability

The risk rating is low, with a CVSS score of 3.4 and no EPSS data available. The flaw is not listed in the CISA KEV catalog, indicating no documented large‑scale exploitation. Nonetheless, the attack vector is inferred to be via the web interface or API, and would require an attacker with network access to the FortiSIEM appliance. Proper access controls and network segmentation reduce the likelihood of a successful attack, but no known public exploit exists as of the latest data.

Generated by OpenCVE AI on August 13, 2026 at 01:56 UTC.

Remediation

Vendor Solution

Upgrade to FortiSIEM version 7.5.1 or above Upgrade to upcoming FortiSIEM version 7.4.3 or above Upgrade to upcoming FortiSIEM version 7.3.6 or above


OpenCVE Recommended Actions

  • Upgrade FortiSIEM to a patched version: 7.5.1 or newer, or at least 7.4.3, or 7.3.6 to include the fix
  • Restrict the FortiSIEM server’s outbound network connections to only trusted destinations and use network segmentation to prevent access to internal resources
  • Enforce strict authentication and role‑based access on the FortiSIEM web interface or API to limit who can submit requests that might trigger SSRF
  • Disable or restrict functionality that allows external URL resolution if it is not required for normal operations

Generated by OpenCVE AI on August 13, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title FortiSIEM Server‑Side Request Forgery Enables Unauthorized Remote Code Execution

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
First Time appeared Fortinet
Fortinet fortisiem
Weaknesses CWE-918
CPEs cpe:2.3:a:fortinet:fortisiem:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.6.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:6.7.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.1.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.3.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.5.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisiem
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortisiem
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-08-12T12:19:02.208Z

Reserved: 2026-08-04T15:01:43.635Z

Link: CVE-2026-70467

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T13:17:25.070

Modified: 2026-08-12T13:17:25.070

Link: CVE-2026-70467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)