CVE-2026-21741
LOWFortiNAC-F 7.2.0-7.6.5 - Authenticated Open Redirect via Crafted CSV File
Title source: llmDescription
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
References (1)
Core 1
Core References
Scores
CVSS v3
2.4
EPSS
0.0021
EPSS Percentile
11.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (4)
Fortinet/FortiNAC-F
7.2.0 - 7.2.9
fortinet/fortinac-f
7.2.0 - 7.6.6
Fortinet/FortiNAC-F
7.4.0 - 7.4.3
Fortinet/FortiNAC-F
7.6.0 - 7.6.5
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026