
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59838 is a Basic Cross-Site Scripting (XSS) vulnerability (CWE-80) in Fortinet FortiSIEM that may allow a privileged administrator to execute unauthorized code or commands via crafted requests to the GUI. It affects FortiSIEM versions 7.4.0, 7.3.0–7.3.4, 7.2.0–7.2.6, and all versions of 7.1, 7.0, 6.7, 6.6, 6.5, and 6.4. The vulnerability was disclosed on July 14–15, 2026, and was reported externally by Anis MESSAOUDI from CPA Bank under responsible disclosure. It carries a CVSS v3.1 base score of 4.8–5.3 (Medium severity), depending on the scoring source (FortiGuard PSIRT, GitHub Advisory).
The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page — Basic XSS), located in the FortiSIEM GUI component, specifically involving a Domain parameter. The root cause is insufficient sanitization of user-supplied input, allowing script-related HTML tags to be injected and rendered in the web interface. Exploitation requires the attacker to be authenticated with high (administrator-level) privileges and requires user interaction — such as a victim administrator viewing a crafted page or parameter — making this a stored or reflected XSS scenario. The specific attack vector (endpoint or parameter) has not been fully disclosed in public advisories (FortiGuard PSIRT, GitHub Advisory).
Successful exploitation allows an authenticated attacker with administrator privileges to execute arbitrary JavaScript in the context of another user's browser session within the FortiSIEM web application. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, and limited confidentiality and integrity impacts within the application scope. Availability is not directly impacted, and the scope is changed (affecting resources beyond the vulnerable component), but the overall impact is constrained by the high privilege requirement and need for user interaction (FortiGuard PSIRT, GitHub Advisory).
<script> or event handler attributes) in the vulnerable Domain parameter or similar input field.<script>, %3Cscript%3E, onerror=, onload=) in parameter values, particularly in Domain-related fields.Fortinet has released patched versions to address this vulnerability: upgrade FortiSIEM 7.4.x to 7.4.1 or above, FortiSIEM 7.3.x to 7.3.5 or above, and FortiSIEM 7.2.x to 7.2.7 or above. Users on FortiSIEM 7.1, 7.0, 6.7, 6.6, 6.5, or 6.4 should migrate to a fixed release, as no patch is available for those branches. As interim mitigations, restrict access to the FortiSIEM web interface to trusted administrators and networks, and consider deploying a Web Application Firewall (WAF) to detect and block XSS payloads (FortiGuard PSIRT).
The vulnerability was reported responsibly by Anis MESSAOUDI from CPA Bank and acknowledged by Fortinet's PSIRT. No significant public researcher commentary, social media discussion, or media coverage has been identified beyond standard vulnerability database aggregation at the time of disclosure (FortiGuard PSIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."