VYPR
advisoryPublished Aug 12, 2026· 1 source

Fortinet FortiSIEM GUI Vulnerable to Server-Side Request Forgery

Fortinet has issued a security advisory detailing a Server-Side Request Forgery (SSRF) vulnerability in the FortiSIEM GUI, potentially allowing authenticated attackers to initiate malicious HTTP requests from affected devices.

Fortinet has released a security advisory for its FortiSIEM GUI, highlighting a critical Server-Side Request Forgery (SSRF) vulnerability. Identified by the Common Weakness Enumeration (CWE) as CWE-918, this flaw permits an authenticated attacker to craft specific HTTP requests that can then be initiated from the targeted FortiSIEM device.

The vulnerability, tracked under advisory FG-IR-26-159, carries a CVSSv3 score of 3.4, indicating a moderate severity. While not critically high, the ability for an authenticated user to make arbitrary HTTP requests from the system can lead to various security risks, including internal network reconnaissance, access to sensitive internal services, or exploitation of other internal vulnerabilities.

Fortinet has provided a detailed breakdown of affected versions across its FortiSIEM product line. Versions 7.5.0 are vulnerable and can be fixed by upgrading to 7.5.1 or later. For FortiSIEM 7.4, versions 7.4.0 through 7.4.2 are affected, with an upcoming release of 7.4.3 intended to address the issue. Similarly, FortiSIEM 7.3 versions 7.3.0 through 7.3.5 require an upgrade to the forthcoming 7.3.6 or higher.

Older versions of FortiSIEM, including all versions of 7.2, 7.1, 7.0, 6.7, 6.6, and 6.5, are also impacted by this SSRF vulnerability. For these legacy versions, Fortinet advises customers to migrate to a fixed release, implying an upgrade to a supported and patched version of the software.

The discovery and responsible disclosure of this vulnerability are credited to external researcher khalooda0x, identified as Khaled ibn Al-Walid. The timeline provided by Fortinet indicates the initial publication of the advisory occurred on August 12, 2026, aligning with the typical disclosure process for security vulnerabilities.

Server-Side Request Forgery vulnerabilities are a persistent threat in web application security. They occur when a web application fetches a remote resource without validating the user-supplied URL. This allows attackers to coerce the application to send crafted requests to an unexpected destination, potentially bypassing firewalls or accessing internal resources that are not directly exposed to the internet.

While the CVSS score of 3.4 suggests moderate risk, the impact can be significant depending on the internal network architecture and the privileges of the authenticated attacker. Organizations using FortiSIEM are strongly encouraged to review the advisory and apply the necessary updates or migration steps to mitigate the risk posed by this SSRF vulnerability.

This advisory serves as a reminder for organizations to maintain up-to-date security software and to regularly review their security posture, especially for management and monitoring tools like SIEM solutions, which often have broad network access.

Synthesized by Vypr AI