Sceawere
Vulnerability Detail
CVE-2026-70467UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FortiSIEM SSRF Remote Code Execution
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.8
- Creation Date
- 3h ago
- Vendor
- Fortinet
- Product
- FortiSIEM
- Attack Type
- Execute unauthorized code or commands
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.8",
"pubDate": "2026-08-12T13:17:25.070Z",
"pubdate": "2026-08-12T13:17:25.070Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in multiple versions of Fortinet FortiSIEM. This security flaw resides within the server-side request handling mechanism, allowing remote attackers to manipulate input parameters and force the vulnerable application into initiating unauthorized outbound network connections to arbitrary destinations. Successful exploitation of this vulnerability can lead to severe security implications, potentially enabling malicious actors to bypass perimeter network defenses, access internal infrastructure resources, and ultimately execute unauthorized code or commands on the targeted system. The affected products encompass FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, along with all versions of FortiSIEM 7.2, 7.1, 7.0, 6.7, 6.6, and 6.5. Exploitation of this vulnerability allows threat actors with network access to leverage the trust boundary of the FortiSIEM server to interact with internal services that are typically isolated from external exposure. Organizations utilizing the impacted software versions face significant risks regarding confidentiality, integrity, and availability of their SIEM infrastructure and connected internal networks. Remediation requires strict adherence to vendor-supplied patches and updates where available, combined with robust network segmentation and egress filtering to limit the potential blast radius of unauthorized outbound requests initiated by the server.",
"technicalDetails": "The vulnerability is classified as a Server-Side Request Forgery (SSRF) flaw affecting Fortinet FortiSIEM across an extensive range of versions, including 7.5.0, 7.4.0 through 7.4.2, 7.3.0 through 7.3.5, and all versions of 7.2, 7.1, 7.0, 6.7, 6.6, and 6.5. The root cause stems from insufficient validation and sanitization of user-supplied URLs or network identifiers within the server-side request processing component. When an application processes external inputs to fetch remote resources without adequately enforcing strict allowlisting or parsing the destination parameters, an attacker can supply malicious Uniform Resource Identifiers to redirect internal HTTP requests.\nThe attack flow begins when an authenticated or unauthenticated attacker—depending on the specific endpoint exposure—submits a crafted payload targeting the vulnerable request-handling functionality. Instead of querying the intended external resource, the FortiSIEM server processes the manipulated input and issues an outbound request on behalf of the attacker. This mechanism allows the attacker to pivot through the server to interact with internal network interfaces, loopback addresses, cloud metadata services, or auxiliary backend services that are otherwise inaccessible from the external network perimeter.\nBy chaining the SSRF vulnerability with internal service interactions or secondary vulnerabilities, an adversary can manipulate the request behavior to induce unintended actions, leak sensitive environment data, or propagate further exploitation leading to remote code or command execution. The network exposure is dictated by the accessibility of the vulnerable FortiSIEM service interface, while privilege and authentication requirements depend on the specific entry point abused during the attack chain. Post-exploitation impact includes full compromise of the host system, lateral movement across the internal enterprise network, and unauthorized administrative control over security information and event management capabilities."
}