Vulnerability Details CVE-2026-21741
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.3%
CVSS Severity
CVSS v3 Score 2.4
Products affected by CVE-2026-21741
-
cpe:2.3:a:fortinet:fortinac-f:7.2.0
-
cpe:2.3:a:fortinet:fortinac-f:7.2.1
-
cpe:2.3:a:fortinet:fortinac-f:7.2.2
-
cpe:2.3:a:fortinet:fortinac-f:7.2.3
-
cpe:2.3:a:fortinet:fortinac-f:7.2.4
-
cpe:2.3:a:fortinet:fortinac-f:7.2.5
-
cpe:2.3:a:fortinet:fortinac-f:7.2.6
-
cpe:2.3:a:fortinet:fortinac-f:7.2.7
-
cpe:2.3:a:fortinet:fortinac-f:7.2.8
-
cpe:2.3:a:fortinet:fortinac-f:7.2.9
-
cpe:2.3:a:fortinet:fortinac-f:7.4.0
-
cpe:2.3:a:fortinet:fortinac-f:7.4.1
-
cpe:2.3:a:fortinet:fortinac-f:7.6.0
-
cpe:2.3:a:fortinet:fortinac-f:7.6.1
-
cpe:2.3:a:fortinet:fortinac-f:7.6.2
-
cpe:2.3:a:fortinet:fortinac-f:7.6.3