← Back to CVE search

CVE-2026-23573

FortiOS

Description

An Improper Neutralization of Input During Web Page Generation (-Cross-site Scripting-) vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.

CVSS 6.1EPSS 0.291%Risk 0.63
View source
Published
2026-07-14 16:16:51
Affected versions
<=7.6.6, <=7.4, <=7.2
Type
Operating system
Last modified
2026-08-11 13:17:59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N