FortinetCVE-2026-22575
Fortinet FortiManager: improper access control
Medium4.9CVE-2026-22575 · Published Sep 8, 2026
An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| FortiManager Product | >= 7.6.0, <= 7.6.4 | No fix yet |
| >= 7.4.0, <= 7.4.10 | No fix yet | |
| >= 7.2.0, <= 7.2.12 | No fix yet | |
| >= 7.0.0, <= 7.0.16 | No fix yet | |
| FortiManager Cloud Product | >= 7.6.2, <= 7.6.4 | No fix yet |
| >= 7.4.1, <= 7.4.10 | No fix yet | |
| >= 7.2.1, <= 7.2.12 | No fix yet | |
| >= 7.0.1, <= 7.0.16 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Fortinet advisories
All Fortinet| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Fortinet FortiSOAR PaaS: improper access control | Medium5.4 | No fix yet |
| Sep 8 | Fortinet FortiClientWindows: improper access control | Medium5.1 | No fix yet |
| Sep 8 | Fortinet FortiSandbox: command injection | High7.2 | No fix yet |
| Sep 8 | Fortinet FortiSIEM: open redirect | Low3.1 | No fix yet |
| Sep 8 | Fortinet FortiAnalyzer: denial of service | Medium6.5 | No fix yet |
| Sep 8 | Fortinet FortiOS: null pointer dereference | Low2.7 | No fix yet |