CVE-2026-22575

Summary

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.

Affected Software

VendorProductVersion RangeStatus
FortinetFortiManager7.6.0 <= 7.6.4affected
FortinetFortiManager7.4.0 <= 7.4.10affected
FortinetFortiManager7.2.0 <= 7.2.12affected
FortinetFortiManager7.0.0 <= 7.0.16affected
FortinetFortiManager6.4.0 <= 6.4.15affected
FortinetFortiManager Cloud7.6.2 <= 7.6.4affected
FortinetFortiManager Cloud7.4.1 <= 7.4.10affected
FortinetFortiManager Cloud7.2.1 <= 7.2.12affected
FortinetFortiManager Cloud7.0.1 <= 7.0.16affected
FortinetFortiManager Cloud6.4.1 <= 6.4.7affected

Weaknesses

  • CWE-284: Improper access control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References