
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59841 is an improper restriction of communication channel to intended endpoints vulnerability (CWE-923) in Fortinet FortiSIEM Windows Agent versions 7.4.0 through 7.4.1. It allows an unauthenticated attacker on the same local network to execute arbitrary code by spoofing the supervisor's hostname when the 'Supers Override' feature is configured. The vulnerability was publicly disclosed on July 14, 2026, with a patch available in version 7.4.2. It carries a CVSSv3 score of 6.9 (Medium) per Fortinet's advisory, though NVD rates it 7.5 (High) (FortiGuard Advisory).
The root cause is classified as CWE-923 (Improper Restriction of Communication Channel to Intended Endpoints). When the FortiSIEM Windows Agent is configured with the 'Supers Override' feature, it fails to properly validate or authenticate the supervisor it communicates with, allowing an adjacent-network attacker to spoof the supervisor's hostname and intercept or manipulate the communication channel. Exploitation requires no authentication and no user interaction, but does require the attacker to be on the same local network segment and for the target agent to have the 'Supers Override' feature enabled. A workaround exists via enabling TLS/SSL certificate verification on the agent (FortiGuard Advisory).
Successful exploitation allows an unauthenticated adjacent-network attacker to execute arbitrary code on systems running the affected FortiSIEM Windows Agent, resulting in full compromise of confidentiality, integrity, and availability on the targeted endpoint. Because FortiSIEM agents are typically deployed on monitored infrastructure hosts, a compromised agent could serve as a foothold for lateral movement within the enterprise environment. The NVD assessment classifies the technical impact as 'total' (FortiGuard Advisory).
Fortinet has released FortiSIEM Windows Agent version 7.4.2 to address this vulnerability; upgrading to 7.4.2 or above is the recommended remediation. As an immediate workaround, administrators should enable the 'Verify Host TLS/SSL certificate' option on the FortiSIEM Windows Agent installation to prevent hostname spoofing attacks. Additionally, restricting network access to affected systems from untrusted adjacent networks reduces exposure. Only versions 7.4.0 and 7.4.1 are affected; all other major versions (7.5, 7.3, 7.2, 7.1, 5.0, 4.x) are not affected (FortiGuard Advisory).
The vulnerability was reported to Fortinet by external researcher Nicola Scremin (@ScreSys) under responsible disclosure, and Fortinet acknowledged the contribution in their advisory. No significant broader media coverage or notable community commentary has been identified beyond standard vulnerability aggregator coverage (FortiGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."