CVE-2026-21741
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may al
Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.2th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet
Description
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
Weakness: CWE-601
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiNAC | Identity / IAM / MFA | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiNAC-F
Vendor remediation
Upgrade to upcoming FortiNAC-F version 7.6.6 or above