Description
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
References (1)
Scores
CVSS v3
2.4
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (4)
Fortinet/FortiNAC-F
7.2.0 - 7.2.9
fortinet/fortinac-f
7.2.0 - 7.6.6
Fortinet/FortiNAC-F
7.4.0 - 7.4.3
Fortinet/FortiNAC-F
7.6.0 - 7.6.5
Published
Apr 14, 2026
Tracked Since
Apr 14, 2026