cbcvebase.
CVE-2025-22256
published 2025-06-10

CVE-2025-22256: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3…

PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.31%
22.9th percentile
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests

Affected

13 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortipam
fortinetfortipam
fortinetfortipam
fortinetfortipam>= 1.0.0 < 1.0.41.0.4
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam>= 1.1.0 < 1.1.31.1.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortipam>= 1.4.0 < 1.4.21.4.2
fortinetfortipam1.4.0 – 1.4.1
fortinetfortisra
fortinetfortisra>= 1.4.0 < 1.4.21.4.2
fortinetfortisra1.4.0 – 1.4.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.