Junglewise Threat Intelligence

CVE-2026-59838: Fortinet FortiSIEM XSS in Domain parameter

CVE-2026-59838 · Severity: medium · CVSS 5.9 · Published 2026-07-15

Vendors: Fortinet.

Executive brief

FortiSIEM is a security management platform used by organizations to monitor and respond to security events across their networks. A vulnerability in its web interface could allow a high-privileged administrator to inject malicious scripts into the system. If another user views the affected page, the attacker could potentially execute unauthorized actions or access sensitive information within the management console.

Technical details

A basic Cross-Site Scripting (XSS) vulnerability exists in Fortinet FortiSIEM due to improper neutralization of script-related HTML tags in the 'Domain' parameter of the GUI. The vulnerability (CWE-80) requires an attacker to have high-level administrative privileges (PR:H) and involves user interaction (UI:R) from another user. By sending a crafted request, an authenticated attacker can inject malicious scripts that execute in the context of the victim's browser session. This could lead to unauthorized command execution or information disclosure within the web management interface. Users are advised to upgrade to versions 7.4.1, 7.3.5, 7.2.7, or later.

Affected products

  • Fortinet FortiSIEM 7.4.0, 7.3.0 through 7.3.4, 7.2.0 through 7.2.6, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions

Timeline

  • 2026-07-14: advisory: Initial publication by Fortinet (FG-IR-26-149)
  • 2026-07-15: disclosed: CVE-2026-59838 published to NVD

References

Related threats