CVE-2026-70467
FortiSIEM vulnerability analysis and mitigation

Overview

CVE-2026-70467 is a Server-Side Request Forgery (SSRF) vulnerability in Fortinet FortiSIEM that may allow an authenticated attacker with high privileges to execute unauthorized code or commands via network requests. It was published on August 12, 2026, and affects FortiSIEM versions 6.4.1–6.4.4, 6.5.0–6.5.3, 6.6.0–6.6.5, 6.7.0–6.7.10, 7.0.0–7.0.4, 7.1.0–7.1.9, 7.2.0–7.2.7, 7.3.0–7.3.5, 7.4.0–7.4.2, and 7.5.0. It carries a CVSS v3.1 base score of 3.8 (Low) (GitHub Advisory, Fortinet PSIRT).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the FortiSIEM web server fails to sufficiently validate or restrict URLs or requests received from upstream components, potentially allowing the server to be directed to make requests to unintended destinations. Exploitation requires network access and high-privilege (administrative or equivalent) credentials, meaning the attack vector is network-based with low complexity but a high privilege prerequisite. The specific attack vector parameter in the official advisory description is noted as a placeholder (<insert attack vector here>), indicating the precise exploitation mechanism has not been fully disclosed publicly (GitHub Advisory, Fortinet PSIRT).

Impact

Successful exploitation of this SSRF vulnerability could allow a high-privileged attacker to execute unauthorized code or commands on the FortiSIEM server, with limited confidentiality and integrity impact (both rated Low) and no availability impact per the CVSS scoring. The vulnerability could be leveraged to make the FortiSIEM server issue requests to internal services or resources not otherwise accessible, potentially enabling reconnaissance of internal network infrastructure or interaction with backend systems. Given FortiSIEM's role as a security information and event management platform, compromise could expose sensitive security telemetry and event data (GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring high privileges to trigger. The EPSS score is approximately 0.257% (18th percentile), indicating a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.

Mitigation and workarounds

Fortinet has released a patch for CVE-2026-70467, available via the Fortinet PSIRT advisory FG-IR-26-159 and the GitHub Advisory GHSA-6p3g-37q6-r7f3 (added August 12, 2026). Organizations should upgrade affected FortiSIEM instances to a patched version as the primary remediation step. As an interim measure, restrict network access to FortiSIEM administrative interfaces to only trusted administrators and monitor for suspicious SSRF activity originating from the FortiSIEM server targeting internal services (Fortinet PSIRT, GitHub Advisory).

Community reactions

Coverage of CVE-2026-70467 has been largely aggregated alongside broader reporting on Fortinet authentication vulnerabilities patched in the same release cycle, with outlets such as CyberSecurityNews, GBHackers, and Cryptika covering the broader Fortinet patch batch rather than this specific CVE in isolation (CyberSecurityNews, GBHackers). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its low CVSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related FortiSIEM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64155CRITICAL9.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJan 13, 2026
CVE-2026-59841HIGH7.5
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJul 14, 2026
CVE-2026-25972MEDIUM6.1
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesMar 10, 2026
CVE-2026-59838MEDIUM4.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoYesJul 15, 2026
CVE-2026-70467LOW3.8
  • FortiSIEM logoFortiSIEM
  • cpe:2.3:a:fortinet:fortisiem
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management