fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-26-159 CVE-2026-70467
LOW
Fortinet FortiSIEM Server-Side Request Forgery
Record summary
CVE-2026-70467 has a selected CVSS score of 3.4 (low).
Description
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiSIEMBrowse Fortinet / FortiSIEMDefault status: unaffected | CVE List | 7.5.0 | affected |
| 7.4.0 to ≤ 7.4.2 | affected | ||
| 7.3.0 to ≤ 7.3.5 | affected | ||
| 7.2.0 to ≤ 7.2.7 | affected | ||
| 7.1.0 to ≤ 7.1.9 | affected | ||
| 7.0.0 to ≤ 7.0.4 | affected | ||
| 6.7.0 to ≤ 6.7.10 | affected | ||
| 6.6.0 to ≤ 6.6.5 | affected | ||
| 6.5.0 to ≤ 6.5.3 | affected | ||
| 6.4.1 to ≤ 6.4.4 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-70467