Fortinet FortiSIEM Vulnerable to Open Redirect Flaw
Fortinet has issued an advisory for an open redirect vulnerability in its FortiSIEM product, allowing authenticated attackers to redirect users to arbitrary websites.

Fortinet has released security advisory FG-IR-26-169, detailing a critical open redirect vulnerability within its FortiSIEM product. This flaw, classified under CWE-601, poses a risk to organizations utilizing the security information and event management solution.
The vulnerability allows an authenticated attacker to manipulate the system into redirecting users to external, potentially malicious websites. The exploitation vector involves crafting specific HTTP requests that trick the FortiSIEM application into performing the redirection. While an attacker must first gain authenticated access to the system, the ease of exploitation once authenticated makes this a notable concern.
The CVSSv3 score for this vulnerability is rated at 2.8, categorizing it as low severity. However, the potential for phishing attacks or directing users to credential harvesting sites means that even low-severity vulnerabilities can have significant downstream impacts, especially in security-focused environments like those using SIEM solutions.
Fortinet has provided details on the affected versions and the necessary steps for remediation. Organizations using FortiSIEM are strongly advised to consult the official advisory and apply any available patches or workarounds promptly to mitigate the risk of exploitation.
Open redirect vulnerabilities, while often considered less severe than remote code execution or privilege escalation flaws, remain a persistent threat. They can serve as a stepping stone in more complex attack chains, leveraging the trust users place in legitimate internal applications to lure them into malicious external sites. The successful exploitation of such a flaw in a SIEM product could undermine the very security monitoring capabilities it is designed to provide.