CVE-2026-21741

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may al

Severity
Low 2.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.2th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet

Description

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.

Weakness: CWE-601

Affected products

Vendor Product Category Matched by
Fortinet FortiNAC Identity / IAM / MFA cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiNAC-F

Vendor remediation

Upgrade to upcoming FortiNAC-F version 7.6.6 or above