cbcvebase.

Fortinet Fortisoar vulnerabilities

33 known vulnerabilities affecting fortinet/fortisoar.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM18

Vulnerabilities

Page 1 of 2
CVE-2026-23708HIGHCVSS 8.1≥ 7.5.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-23708 [HIGH] CWE-287 CVE-2026-23708: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR Pa A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and
nvdfortinet
CVE-2026-22155HIGHCVSS 7.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-22155 [HIGH] CWE-319 CVE-2026-22155: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-pre
nvd
CVE-2025-59809MEDIUMCVSS 4.3≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.3+1 more2026-04-14
CVE-2025-59809 [MEDIUM] CWE-918 CVE-2025-59809: A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR Paa A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through
nvdfortinet
CVE-2026-22154MEDIUMCVSS 5.4≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-22154 [MEDIUM] CWE-79 CVE-2026-22154: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-pre
nvdfortinet
CVE-2026-22573MEDIUMCVSS 6.5≥ 7.3.0, ≤ 7.3.3≥ 7.4.0, ≤ 7.4.5+2 more2026-04-14
CVE-2026-22573 [MEDIUM] CWE-22 CVE-2026-22573: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all
nvdfortinet
CVE-2026-21742MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-21742 [MEDIUM] CWE-319 CVE-2026-21742: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-p
nvdfortinet
CVE-2026-22574MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.52026-04-14
CVE-2026-22574 [MEDIUM] CWE-257 CVE-2026-22574: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7 A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvdfortinet
CVE-2026-22576MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.52026-04-14
CVE-2026-22576 [MEDIUM] CWE-257 CVE-2026-22576: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7 A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvdfortinet
CVE-2025-54659MEDIUMCVSS 5.82026-03-10
CVE-2025-54659 [MEDIUM] CWE-22 Path traversal vulnerability in FortiSOAR Agent Connector Bridge server FG-IR-26-084: Path traversal vulnerability in FortiSOAR Agent Connector Bridge server An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar u
fortinet
CVE-2025-59810MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.2≥ 7.6.0, < 7.6.32025-12-09
CVE-2025-59810 [MEDIUM] CWE-284 CVE-2025-59810: An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR P An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions
nvdfortinet
CVE-2025-59808MEDIUMCVSS 6.8≥ 7.3.0, < 7.5.2≥ 7.6.0, ≤ 7.6.32025-12-09
CVE-2025-59808 [MEDIUM] CWE-620 CVE-2025-59808: An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR
nvdfortinet
CVE-2024-48891HIGHCVSS 7.0≥ 7.3.0, < 7.5.2≥ 7.6.0, < 7.6.22025-10-14
CVE-2024-48891 [HIGH] CWE-78 CVE-2024-48891: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local
nvdfortinet
CVE-2024-48892MEDIUMCVSS 4.9≥ 7.3.0, < 7.5.2v7.6.0+3 more2025-08-12
CVE-2024-48892 [MEDIUM] CWE-23 CVE-2024-48892: A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all ve A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
nvdfortinet
CVE-2025-32932MEDIUMCVSS 5.4≥ 6.4.0, < 7.5.2≥ 7.6.0, < 7.6.2+8 more2025-08-12
CVE-2025-32932 [MEDIUM] CWE-79 CVE-2025-32932: An Improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored mal
nvdfortinet
CVE-2024-21760HIGHCVSS 8.4≥ 6.4.0, ≤ 7.4.5≥ 7.4.0, ≤ 7.4.5+4 more2025-03-18
CVE-2024-21760 [HIGH] CWE-94 CVE-2024-21760: An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Con An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.
nvdfortinet
CVE-2022-23439MEDIUMCVSS 6.1≥ 6.4.0, < 7.3.02025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvdfortinet
CVE-2024-48890HIGHCVSS 8.8v7.5.02025-01-14
CVE-2024-48890 [HIGH] CWE-78 CVE-2024-48890: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
nvdfortinet
CVE-2024-47572HIGHCVSS 8.0≥ 7.2.1, ≤ 7.2.2≥ 7.3.0, < 7.3.3+3 more2025-01-14
CVE-2024-47572 [HIGH] CWE-1236 CVE-2024-47572: An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4 An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
nvdfortinet
CVE-2024-48893MEDIUMCVSS 5.4≥ 7.2.1, ≤ 7.3.3≥ 7.3.0, ≤ 7.3.32025-01-14
CVE-2024-48893 [MEDIUM] CWE-79 CVE-2024-48893: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
nvdfortinet
CVE-2024-36510MEDIUMCVSS 5.3≥ 6.4.0, < 7.3.3≥ 7.4.0, < 7.4.5+7 more2025-01-14
CVE-2024-36510 [MEDIUM] CWE-204 CVE-2024-36510: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7. An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
nvdfortinet