Fortinet Fortisoar vulnerabilities
32 known vulnerabilities affecting fortinet/fortisoar.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM17
Vulnerabilities
Page 1 of 2
CVE-2024-48890P2HIGHCVSS 8.8v7.5.02025-01-14
CVE-2024-48890 [HIGH] CWE-78 CVE-2024-48890: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
nvd
CVE-2026-23708P3HIGHCVSS 8.1≥ 7.5.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-23708 [HIGH] CWE-287 CVE-2026-23708: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR Pa
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and
nvd
CVE-2023-27995P3HIGHCVSS 8.8≥ 7.3.0, < 7.3.2≥ 7.3.0, ≤ 7.3.12023-04-11
CVE-2023-27995 [HIGH] CWE-1336 CVE-2023-27995: A improper neutralization of special elements used in a template engine vulnerability in Fortinet Fo
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
nvd
CVE-2023-23775P3HIGHCVSS 8.8≥ 7.0.0, < 7.2.1v7.2.0+1 more2024-06-11
CVE-2023-23775 [HIGH] CWE-89 CVE-2023-23775: Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerab
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
nvd
CVE-2022-35847P3HIGHCVSS 8.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.3+1 more2022-09-06
CVE-2022-35847 [HIGH] CWE-94 CVE-2022-35847: An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
nvd
CVE-2022-29061P3HIGHCVSS 7.2≥ 6.4.1, ≤ 6.4.4≥ 7.0.0, < 7.0.3+1 more2022-09-09
CVE-2022-29061 [HIGH] CWE-78 CVE-2022-29061: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
nvd
CVE-2024-45327P3HIGHCVSS 7.5≥ 7.0.0, < 7.3.3≥ 7.4.0, < 7.4.4+4 more2024-09-11
CVE-2024-45327 [HIGH] CWE-307 CVE-2024-45327: An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 th
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
nvd
CVE-2024-21760P3HIGHCVSS 8.4≥ 6.4.0, ≤ 7.4.5≥ 7.4.0, ≤ 7.4.5+4 more2025-03-18
CVE-2024-21760 [HIGH] CWE-94 CVE-2024-21760: An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Con
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.
nvd
CVE-2022-23443P3HIGHCVSS 7.5≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, ≤ 7.0.2+1 more2022-05-04
CVE-2022-23443 [HIGH] CVE-2022-23443: An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to ac
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
nvd
CVE-2024-47572P3HIGHCVSS 8.0≥ 7.2.1, ≤ 7.2.2≥ 7.3.0, < 7.3.3+3 more2025-01-14
CVE-2024-47572 [HIGH] CWE-1236 CVE-2024-47572: An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
nvd
CVE-2025-59808P3MEDIUMCVSS 6.8≥ 7.3.0, < 7.5.2≥ 7.6.0, ≤ 7.6.32025-12-09
CVE-2025-59808 [MEDIUM] CWE-620 CVE-2025-59808: An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR
nvd
CVE-2026-22573P3MEDIUMCVSS 6.5≥ 7.3.0, ≤ 7.3.3≥ 7.4.0, ≤ 7.4.5+2 more2026-04-14
CVE-2026-22573 [MEDIUM] CWE-22 CVE-2026-22573: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all
nvd
CVE-2022-30298P3HIGHCVSS 7.8≥ 6.4.0, ≤ 6.4.4≥ 7.0.0, < 7.0.3+1 more2022-09-06
CVE-2022-30298 [HIGH] CWE-269 CVE-2022-30298: An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
nvd
CVE-2023-26211P3CRITICALCVSS 9.0≥ 6.4.0, < 7.3.3v7.4.0+5 more2024-08-13
CVE-2023-26211 [CRITICAL] CWE-79 CVE-2023-26211: An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
nvd
CVE-2026-22155P3HIGHCVSS 7.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.42026-04-14
CVE-2026-22155 [HIGH] CWE-319 CVE-2026-22155: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-pre
nvd
CVE-2023-25605P3HIGHCVSS 7.2≥ 7.3.0, < 7.3.2≥ 7.3.0, ≤ 7.3.12023-03-07
CVE-2023-25605 [HIGH] CWE-284 CVE-2023-25605: A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authe
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
nvd
CVE-2024-48891P3HIGHCVSS 7.0≥ 7.3.0, < 7.5.2≥ 7.6.0, < 7.6.22025-10-14
CVE-2024-48891 [HIGH] CWE-78 CVE-2024-48891: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local
nvd
CVE-2026-22574P3MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.52026-04-14
CVE-2026-22574 [MEDIUM] CWE-257 CVE-2026-22574: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvd
CVE-2025-59810P3MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.2≥ 7.6.0, < 7.6.32025-12-09
CVE-2025-59810 [MEDIUM] CWE-284 CVE-2025-59810: An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR P
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions
nvd
CVE-2026-22576P3MEDIUMCVSS 6.5≥ 7.3.0, < 7.5.3≥ 7.6.0, < 7.6.52026-04-14
CVE-2026-22576 [MEDIUM] CWE-257 CVE-2026-22576: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvd
1 / 2Next →