
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70467 is a Server-Side Request Forgery (SSRF) vulnerability in Fortinet FortiSIEM that may allow an authenticated attacker with high privileges to execute unauthorized code or commands via network requests. It was published on August 12, 2026, and affects FortiSIEM versions 6.4.1–6.4.4, 6.5.0–6.5.3, 6.6.0–6.6.5, 6.7.0–6.7.10, 7.0.0–7.0.4, 7.1.0–7.1.9, 7.2.0–7.2.7, 7.3.0–7.3.5, 7.4.0–7.4.2, and 7.5.0. It carries a CVSS v3.1 base score of 3.8 (Low) (GitHub Advisory, Fortinet PSIRT).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the FortiSIEM web server fails to sufficiently validate or restrict URLs or requests received from upstream components, potentially allowing the server to be directed to make requests to unintended destinations. Exploitation requires network access and high-privilege (administrative or equivalent) credentials, meaning the attack vector is network-based with low complexity but a high privilege prerequisite. The specific attack vector parameter in the official advisory description is noted as a placeholder (<insert attack vector here>), indicating the precise exploitation mechanism has not been fully disclosed publicly (GitHub Advisory, Fortinet PSIRT).
Successful exploitation of this SSRF vulnerability could allow a high-privileged attacker to execute unauthorized code or commands on the FortiSIEM server, with limited confidentiality and integrity impact (both rated Low) and no availability impact per the CVSS scoring. The vulnerability could be leveraged to make the FortiSIEM server issue requests to internal services or resources not otherwise accessible, potentially enabling reconnaissance of internal network infrastructure or interaction with backend systems. Given FortiSIEM's role as a security information and event management platform, compromise could expose sensitive security telemetry and event data (GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring high privileges to trigger. The EPSS score is approximately 0.257% (18th percentile), indicating a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.
Fortinet has released a patch for CVE-2026-70467, available via the Fortinet PSIRT advisory FG-IR-26-159 and the GitHub Advisory GHSA-6p3g-37q6-r7f3 (added August 12, 2026). Organizations should upgrade affected FortiSIEM instances to a patched version as the primary remediation step. As an interim measure, restrict network access to FortiSIEM administrative interfaces to only trusted administrators and monitor for suspicious SSRF activity originating from the FortiSIEM server targeting internal services (Fortinet PSIRT, GitHub Advisory).
Coverage of CVE-2026-70467 has been largely aggregated alongside broader reporting on Fortinet authentication vulnerabilities patched in the same release cycle, with outlets such as CyberSecurityNews, GBHackers, and Cryptika covering the broader Fortinet patch batch rather than this specific CVE in isolation (CyberSecurityNews, GBHackers). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its low CVSS score and absence of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."