FORTINET Security Advisory
Published Date: Not specified
Advisory Summary
🔔 🛑 Open Redirect Weakness in FortiSIEM (CWE-601)
FortiSIEM is reported to have an open redirect vulnerability (CVSSv3 2.8) where an authenticated attacker can craft HTTP requests to redirect users to any untrusted website.
- Phishing enablement: Redirects can be used to land analysts/operators on lookalike login pages or malicious content.
- Trust boundary abuse: Even without full system compromise, the ability to steer users can undermine SOC workflows and escalation chains.
- Reduced friction for social engineering: Authenticated attackers can leverage existing access to target high-value users (IR leads, SIEM admins).
🛠️ Risks / threat scenario
An attacker with valid credentials uses crafted parameters to force the application to redirect to an attacker-controlled domain—potentially capturing credentials, session tokens (via additional attacks), or prompting unsafe actions.
- Patch/Update: Apply the Fortinet PSIRT-recommended update referenced below (revised 2026-09-08).
- Validate redirect parameters: If immediate patching isn’t possible, review any exposed redirect-handling logic and restrict allowed targets.
- Harden user protections: Enforce browser protections (e.g., conditional access, MFA, and strong session handling) to reduce the payoff of any redirect-based social engineering.
- Monitor for exploitation: Look for unusual redirect patterns originating from authenticated sessions (web/API logs referencing redirect parameters).
📌
đź”— https://fortiguard.fortinet.com/psirt/FG-IR-26-169
-601