CVE-2026-59841 Details
Description
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
A vulnerability exists in Fortinet FortiSIEM Windows Agent versions 7.4.0 through 7.4.1, due to improper restriction of communication channels to intended endpoints. This vulnerability may allow an attacker on the same local network to escalate privileges by spoofing the supervisor's hostname, particularly when the Windows device has the 'Supers Override' feature enabled.
Users can upgrade to Fortinet FortiSIEM Windows Agent version 7.4.2 or above to address this vulnerability. As a workaround, enable the 'Verify Host TLS/SSL certificate' option during FortiSIEM Windows Agent installation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-155 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortisiem | >= 7.4.0, < 7.4.2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |