Junglewise Threat Intelligence

CVE-2026-84389: Fortinet FortiSIEM open redirect vulnerability

CVE-2026-84389 · Severity: low · CVSS 3.1 · Published 2026-09-08

Vendors: Fortinet.

Executive brief

FortiSIEM is a security information and event management platform used by enterprises to monitor and analyze security events across their infrastructure. An open redirect vulnerability allows an authenticated attacker to redirect users to arbitrary external websites through specially crafted HTTP requests, potentially enabling phishing attacks or malware distribution.

Technical details

This is a URL open redirect vulnerability (CWE-601) in the FortiSIEM GUI that allows authenticated attackers to craft HTTP requests containing malicious redirect parameters, causing the application to redirect users to untrusted external sites. The vulnerability affects FortiSIEM versions 7.4.1 through 7.4.2 and 7.5.0 through 7.5.1. Attack requires authentication and the victim must follow the malicious link. An attacker can leverage this to redirect users to phishing pages or malware distribution sites. Fortinet has released patches; users should upgrade to FortiSIEM 7.5.2 or above (7.5.x) or migrate to fixed releases (7.4.x).

Affected products

  • Fortinet FortiSIEM 7.4.1 through 7.4.2, 7.5.0 through 7.5.1

Timeline

  • 2026-09-08: disclosed

References

Related threats