CVE-2023-26211: Fortinet Fortisoar

Critical severity, CVSS 9.0. EPSS: 0.7% chance of exploitation in the next 30 days.

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.

Affected products

  • Fortinet Fortisoar: from 6.4.0, before 7.3.3 (fixed in 7.3.3); version 7.4.0 only

Published 2024-08-13. Last modified 2026-06-17.