
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25972 is a reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiSIEM's error page that may allow a remote unauthenticated attacker to inject arbitrary data via spoofed URL parameters, enabling social engineering attacks. It affects FortiSIEM versions 7.3.0 through 7.3.4 and 7.4.0; versions 7.2 and earlier, 7.5, and later are not affected. The vulnerability was discovered during an internal audit commissioned by Fortinet and publicly disclosed on March 10, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, and 4.1 (Medium) per Fortinet's own advisory (Fortinet PSIRT, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and resides specifically in FortiSIEM's error page component. An unauthenticated remote attacker can craft malicious URL parameters that are reflected back into the error page without proper sanitization or encoding, allowing arbitrary HTML or script content to be rendered in a victim's browser. Exploitation requires user interaction — a victim must click a specially crafted link — making this a reflected (non-persistent) XSS variant. The attack vector is network-based with low complexity and no privileges required (Fortinet PSIRT).
Successful exploitation allows an attacker to inject arbitrary content into the FortiSIEM web interface as rendered in a victim's browser, primarily enabling social engineering attacks such as phishing, credential harvesting, or tricking users into performing unintended actions. Confidentiality impact is low (limited data exposure through session context), integrity impact is low (page content manipulation), and there is no availability impact. The vulnerability does not provide direct access to backend systems or sensitive data, but could be chained with other techniques to escalate impact (Fortinet PSIRT, Red Hat CVE).
https://<target>/error?param=<script>alert(document.cookie)</script>).<script>, javascript:, onerror=, onload=).Fortinet has released patched versions to address this vulnerability. Users running FortiSIEM 7.3.0 through 7.3.4 should upgrade to version 7.3.5 or later; users on FortiSIEM 7.4.0 should upgrade to version 7.4.1 or above. As interim mitigations, restrict network access to FortiSIEM management interfaces to trusted IP ranges, implement security awareness training to help users recognize phishing attempts via spoofed URLs, and monitor web access logs for suspicious URL parameter patterns (Fortinet PSIRT).
The vulnerability received limited public attention given its medium severity and lack of active exploitation. It was tracked by standard vulnerability aggregators including VulnDB, Wiz, and Radar/Offseq shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond routine CVE tracking (Fortinet PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."