Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Fortinet PSIRT

Server-Side Request Forgery (SSRF)

  • What: Server-Side Request Forgery vulnerability in FortiSIEM GUI
  • Impact: Authenticated attacker could send HTTP requests from the targeted device
Read Full Article →

PSIRT Server-Side Request Forgery (SSRF) Summary A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests Version Affected Solution FortiSIEM 7.5 7.5.0 Upgrade to 7.5.1 or above FortiSIEM 7.4 7.4.0 through 7.4.2 Upgrade to upcoming 7.4.3 or above FortiSIEM 7.3 7.3.0 through 7.3.5 Upgrade to upcoming 7.3.6 or above FortiSIEM 7.2 7.2 all versions Migrate to a fixed release FortiSIEM 7.1 7.1 all versions Migrate to a fixed release FortiSIEM 7.0 7.0 all versions Migrate to a fixed release FortiSIEM 6.7 6.7 all versions Migrate to a fixed release FortiSIEM 6.6 6.6 all versions Migrate to a fixed release FortiSIEM 6.5 6.5 all versions Migrate to a fixed release Acknowledgement Discovered and Responsibly reported by external researcher khalooda0x - Khaled ibn Al-Walid. Timeline 2026-08-12: Initial publication IR Number FG-IR-26-159 Published Date Aug 12, 2026 Component GUI Severity Low Discovered External Attack Type Authenticated Known Exploited No CVSSv3 Score 3.4 Impact Execute unauthorized code or commands CVE ID CVE-2026-70467 Download CVRF CSAF

Share this article