Junglewise Threat Intelligence

CVE-2026-59841: Fortinet FortiSIEM Windows Agent privilege escalation via hostname spoofing

CVE-2026-59841 · Severity: high · CVSS 7.5 · Published 2026-07-14

Vendors: Fortinet.

Executive brief

FortiSIEM Windows Agent is a software component used to monitor and collect security logs from Windows devices for centralized analysis. A security flaw in how the agent communicates with its management server could allow an attacker on the same local network to impersonate the server. If successful, the attacker could gain elevated control over the monitored Windows device or execute unauthorized commands, potentially compromising the integrity of the security monitoring system.

Technical details

An Improper Restriction of Communication Channel to Intended Endpoints (CWE-923) vulnerability exists in FortiSIEM Windows Agent versions 7.4.0 through 7.4.1. The flaw occurs when the 'Supers Override' feature is enabled, failing to properly validate the supervisor's address. An unauthenticated attacker located on the same local network (adjacent) can exploit this by spoofing the supervisor's hostname to intercept or redirect communications. This can lead to arbitrary code execution and privilege escalation on the host machine. The issue is resolved in FortiSIEM Windows Agent version 7.4.2.

Affected products

  • Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1

Timeline

  • 2026-07-14: advisory: Initial publication of FG-IR-26-155
  • 2026-07-14: disclosed

References