---
id: CVE-2026-70467
title: >-
  A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM
  7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM
  7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions,
  FortiSIEM 6…
summary: >-
  A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM
  7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM
  7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions,
  FortiSIEM 6…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: fortinet
product: fortisiem
affected:
  - 'fortisiem >= 6.5.0, < 7.3.6'
  - 'fortisiem >= 7.4.0, < 7.4.3'
  - fortisiem = 7.5.0
patched:
  - fortisiem 7.4.3
published: '2026-08-12'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:00:55.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70467'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-159'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00255
epssPercentile: 0.15165
ingestedAt: '2026-09-08T21:11:12.275Z'
---

## Overview

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

## Affected

- `fortisiem >= 6.5.0, < 7.3.6`
- `fortisiem >= 7.4.0, < 7.4.3`
- `fortisiem = 7.5.0`

## Remediation

Upgrade past the affected range:

- `fortisiem 7.4.3`
