VDB

CVE-2026-59838

CVE-2026-59838 PUBLISHED CVSS 5.3 MEDIUM

Reported by fortinet · Published July 15, 2026

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Risk Scores

CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
FortinetFortiSIEM7.4.0, 7.3.0, 7.2.0
FortinetFortiSIEM7.4.0, 7.3.0, 7.2.0

Timeline

  • Jul 15, 2026 Coalition ESS Score
  • Jul 15, 2026 CVE Published
  • Jul 15, 2026 CVE Updated
  • Jul 15, 2026 Security Advisory
  • Jul 16, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›