Open Redirection via Import CSV option
Summary
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.
| Version | Affected | Solution |
|---|---|---|
| FortiNAC-F 7.6 | 7.6.0 through 7.6.5 | Upgrade to 7.6.6 or above |
| FortiNAC-F 7.4 | 7.4 all versions | Migrate to a fixed release |
| FortiNAC-F 7.2 | 7.2 all versions | Migrate to a fixed release |
Acknowledgement
Discovered during an independent audit commissioned by Fortinet.Timeline
2026-04-14: Initial publication