Skip to content
FortinetCVE-2026-22575

Fortinet FortiManager: improper access control

Medium4.9CVE-2026-22575 · Published Sep 8, 2026

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.

Fortinet advisory

Affected versions

PackageAffectedFixed in
FortiManager
Product
>= 7.6.0, <= 7.6.4No fix yet
>= 7.4.0, <= 7.4.10No fix yet
>= 7.2.0, <= 7.2.12No fix yet
>= 7.0.0, <= 7.0.16No fix yet
FortiManager Cloud
Product
>= 7.6.2, <= 7.6.4No fix yet
>= 7.4.1, <= 7.4.10No fix yet
>= 7.2.1, <= 7.2.12No fix yet
>= 7.0.1, <= 7.0.16No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-284

More Fortinet advisories

All Fortinet
Advisory
Fortinet FortiSOAR PaaS: improper access control
Medium5.4Sep 8
Fortinet FortiClientWindows: improper access control
Medium5.1Sep 8
Fortinet FortiSandbox: command injection
High7.2Sep 8
Fortinet FortiSIEM: open redirect
Low3.1Sep 8
Fortinet FortiAnalyzer: denial of service
Medium6.5Sep 8
Fortinet FortiOS: null pointer dereference
Low2.7Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.