CVE-2026-21741

LOW

Fortinet FortiNAC-F < 7.6.5 - Open Redirect

Title source: rule
STIX 2.1

Description

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.

Scores

CVSS v3 2.4
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (4)
Fortinet/FortiNAC-F 7.2.0 - 7.2.9
fortinet/fortinac-f 7.2.0 - 7.6.6
Fortinet/FortiNAC-F 7.4.0 - 7.4.3
Fortinet/FortiNAC-F 7.6.0 - 7.6.5
Published Apr 14, 2026
Tracked Since Apr 14, 2026