Fortinet Fortisoar On-Premise vulnerabilities
12 known vulnerabilities affecting fortinet/fortisoar_on-premise.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2026-23708HIGHCVSS 8.1≥ 7.6.0, ≤ 7.6.3≥ 7.5.0, ≤ 7.5.22026-04-14
CVE-2026-23708 [HIGH] CWE-287 CVE-2026-23708: A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR Pa
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and
nvd
CVE-2026-22155HIGHCVSS 7.5≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2026-04-14
CVE-2026-22155 [HIGH] CWE-319 CVE-2026-22155: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-pre
nvd
CVE-2025-59809MEDIUMCVSS 4.3v7.6.4≥ 7.6.0, ≤ 7.6.2+3 more2026-04-14
CVE-2025-59809 [MEDIUM] CWE-918 CVE-2025-59809: A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR Paa
A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through
nvd
CVE-2026-22154MEDIUMCVSS 5.4≥ 7.6.0, ≤ 7.6.3≥ 7.5.0, ≤ 7.5.2+2 more2026-04-14
CVE-2026-22154 [MEDIUM] CWE-79 CVE-2026-22154: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-pre
nvd
CVE-2026-22573MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.3≥ 7.5.0, ≤ 7.5.3+2 more2026-04-14
CVE-2026-22573 [MEDIUM] CWE-22 CVE-2026-22573: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all
nvd
CVE-2026-21742MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2026-04-14
CVE-2026-21742 [MEDIUM] CWE-319 CVE-2026-21742: A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thr
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-p
nvd
CVE-2026-22574MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.4≥ 7.5.0, ≤ 7.5.2+2 more2026-04-14
CVE-2026-22574 [MEDIUM] CWE-257 CVE-2026-22574: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvd
CVE-2026-22576MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.4≥ 7.5.0, ≤ 7.5.2+2 more2026-04-14
CVE-2026-22576 [MEDIUM] CWE-257 CVE-2026-22576: A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise
nvd
CVE-2025-59808MEDIUMCVSS 6.8≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2025-12-09
CVE-2025-59808 [MEDIUM] CWE-620 CVE-2025-59808: An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR
nvd
CVE-2025-59810MEDIUMCVSS 6.5≥ 7.6.0, ≤ 7.6.2≥ 7.5.0, ≤ 7.5.1+2 more2025-12-09
CVE-2025-59810 [MEDIUM] CWE-284 CVE-2025-59810: An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR P
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions
nvd
CVE-2024-48891HIGHCVSS 7.0v7.6.0≥ 7.5.0, ≤ 7.5.1+2 more2025-10-14
CVE-2024-48891 [HIGH] CWE-78 CVE-2024-48891: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local
nvd
CVE-2022-23439MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.2.2≥ 7.0.0, ≤ 7.0.3+2 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd