CVE-2026-22575 PUBLISHED

Assigner: fortinet
Reserved: 07.01.2026 Published: 08.09.2026 Updated: 08.09.2026

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C
CVSS Score: 4.7

Product Status

Vendor Fortinet
Product FortiManager
Versions Default: unaffected
  • affected from 7.6.0 to 7.6.4 (incl.)
  • affected from 7.4.0 to 7.4.10 (incl.)
  • affected from 7.2.0 to 7.2.12 (incl.)
  • affected from 7.0.0 to 7.0.16 (incl.)
  • affected from 6.4.0 to 6.4.15 (incl.)
Vendor Fortinet
Product FortiManager Cloud
Versions Default: unaffected
  • affected from 7.6.2 to 7.6.4 (incl.)
  • affected from 7.4.1 to 7.4.10 (incl.)
  • affected from 7.2.1 to 7.2.12 (incl.)
  • affected from 7.0.1 to 7.0.16 (incl.)
  • affected from 6.4.1 to 6.4.7 (incl.)

Solutions

Upgrade to FortiManager version 8.0.0 or above Upgrade to FortiManager version 7.6.5 or above Upgrade to FortiManager version 7.4.11 or above Upgrade to upcoming FortiManager Cloud version 8.0.0 or above Upgrade to FortiManager Cloud version 7.6.5 or above Upgrade to upcoming FortiManager Cloud version 7.4.11 or above

References

Problem Types

  • Improper access control CWE