CVE-2026-25972
FortiSIEM vulnerability analysis and mitigation

Overview

CVE-2026-25972 is a reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiSIEM's error page that may allow a remote unauthenticated attacker to inject arbitrary data via spoofed URL parameters, enabling social engineering attacks. It affects FortiSIEM versions 7.3.0 through 7.3.4 and 7.4.0; versions 7.2 and earlier, 7.5, and later are not affected. The vulnerability was discovered during an internal audit commissioned by Fortinet and publicly disclosed on March 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, and 4.1 (Medium) per Fortinet's own advisory (Fortinet PSIRT, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and resides specifically in FortiSIEM's error page component. An unauthenticated remote attacker can craft malicious URL parameters that are reflected back into the error page without proper sanitization or encoding, allowing arbitrary HTML or script content to be rendered in a victim's browser. Exploitation requires user interaction — a victim must click a specially crafted link — making this a reflected (non-persistent) XSS variant. The attack vector is network-based with low complexity and no privileges required (Fortinet PSIRT).

Impact

Successful exploitation allows an attacker to inject arbitrary content into the FortiSIEM web interface as rendered in a victim's browser, primarily enabling social engineering attacks such as phishing, credential harvesting, or tricking users into performing unintended actions. Confidentiality impact is low (limited data exposure through session context), integrity impact is low (page content manipulation), and there is no availability impact. The vulnerability does not provide direct access to backend systems or sensitive data, but could be chained with other techniques to escalate impact (Fortinet PSIRT, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing FortiSIEM instances running versions 7.3.0–7.3.4 or 7.4.0 using tools like Shodan or Censys, searching for FortiSIEM login or error pages.
  2. Craft malicious URL: Construct a URL targeting FortiSIEM's error page with a spoofed or malicious URL parameter containing an XSS payload (e.g., https://<target>/error?param=<script>alert(document.cookie)</script>).
  3. Deliver the link: Send the crafted URL to a target user via phishing email, instant message, or other social engineering channel, disguising it as a legitimate FortiSIEM link.
  4. Victim interaction: When the victim clicks the link and their browser loads the error page, the unsanitized parameter is reflected into the page HTML and the injected script executes in the victim's browser context.
  5. Achieve objective: The attacker can use the executed script to steal session cookies, redirect the user to a phishing page, display fake login prompts, or perform other browser-based actions on behalf of the victim (Fortinet PSIRT).

Indicators of compromise

  • Network: HTTP requests to FortiSIEM error pages containing URL-encoded script tags or HTML injection patterns in query parameters (e.g., <script>, javascript:, onerror=, onload=).
  • Logs: Web server or FortiSIEM access logs showing GET requests to error page endpoints with anomalous or encoded parameter values; repeated requests from external IPs with varying XSS payloads in URL parameters.
  • User Reports: Users reporting unexpected redirects, pop-ups, or login prompts when accessing FortiSIEM links received via email or messaging platforms.

Mitigation and workarounds

Fortinet has released patched versions to address this vulnerability. Users running FortiSIEM 7.3.0 through 7.3.4 should upgrade to version 7.3.5 or later; users on FortiSIEM 7.4.0 should upgrade to version 7.4.1 or above. As interim mitigations, restrict network access to FortiSIEM management interfaces to trusted IP ranges, implement security awareness training to help users recognize phishing attempts via spoofed URLs, and monitor web access logs for suspicious URL parameter patterns (Fortinet PSIRT).

Community reactions

The vulnerability received limited public attention given its medium severity and lack of active exploitation. It was tracked by standard vulnerability aggregators including VulnDB, Wiz, and Radar/Offseq shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond routine CVE tracking (Fortinet PSIRT).

Additional resources


SourceThis report was generated using AI

Related FortiSIEM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64155CRITICAL9.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJan 13, 2026
CVE-2026-59841HIGH7.5
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJul 14, 2026
CVE-2026-25972MEDIUM6.1
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesMar 10, 2026
CVE-2026-59838MEDIUM4.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJul 15, 2026
CVE-2025-58324MEDIUM4.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesOct 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management