Security Policy Bypass in Forcepoint Security Engine (NGFW)
Summary
| CVE | CVE-2026-12974 |
|---|---|
| State | PUBLISHED |
| Assigner | forcepoint |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-23 14:17:06 UTC |
| Updated | 2026-09-23 17:58:26 UTC |
| Description | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0. |
Risk And Classification
Primary CVSS: v4.0 7.9 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-183 | CWE-1284 | CWE-1284 CWE-1284 Improper validation of specified quantity in input | CWE-183 CWE-183 Permissive list of allowed inputs
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.9 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/C... |
| 4.0 | CNA | CVSS | 7.9 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Forcepoint | Forcepoint Security Engine NGFW | affected 7.1.0 7.1.13 semver | Not specified |
| CNA | Forcepoint | Forcepoint Security Engine NGFW | affected 7.3.0 7.3.1 semver | Not specified |
| CNA | Forcepoint | Forcepoint Security Engine NGFW | affected 7.3.3 semver | Not specified |
| CNA | Forcepoint | Forcepoint Security Engine NGFW | affected 7.4.0 7.4.1 semver | Not specified |
| CNA | Forcepoint | Forcepoint Security Engine NGFW | affected 7.5.0 custom | Not specified |
| CNA | Forcepoint | Forcepoint Security Engine NGFW | unaffected 7.3.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.forcepoint.com/s/article/Security-Advisory-Security-Policy-Bypass-in-Forcepo... | [email protected] | support.forcepoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tuukka Vainio from the University of Turku (en)
Additional Advisory Data
Solutions
CNA: FlexEdge Secure SD-WAN Engine 7.1.14
CNA: Network Security Platform Security Engine 7.3.4
CNA: Network Security Platform Security Engine 7.4.2
CNA: Network Security Platform Security Engine 7.5.1