Executive brief
A security vulnerability exists in the Agentless SSL-VPN feature of several Fortinet products, including FortiOS and FortiProxy. This feature allows users to access internal resources through a web browser without installing additional software. An attacker could exploit this flaw to execute malicious scripts in a user's browser session, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] exists in the Agentless SSL-VPN component of multiple Fortinet products. The flaw is a reflected XSS that occurs when the application fails to properly sanitize user-supplied input before including it in a web page. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking or unauthorized command execution. The vulnerability only impacts systems where the Agentless SSL-VPN feature is enabled.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.6, 7.4 all versions, 7.2 all versions
- Fortinet FortiPAM 1.8.0, 1.7 all versions, 1.6 all versions, 1.5 all versions, 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions
- Fortinet FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.9
- Fortinet FortiSwitch-Manager All versions using Agentless SSL-VPN
Timeline
- 2026-07-14: advisory: Initial publication by Fortinet
- 2026-07-14: disclosed: Reported by the UK's National Cyber Security Centre (NCSC)