VDB

CVE-2026-22575

CVE-2026-22575 PUBLISHED CVSS 4.7 MEDIUM

Reported by fortinet · Published September 8, 2026

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.

Risk Scores

CVSS 3.1
4.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
FortinetFortiManager7.6.0, 7.4.0, 7.2.0
FortinetFortiManager Cloud7.6.2, 7.4.1, 7.2.1
FortinetFortiManager6.4.0, 7.6.0, 7.4.0
FortinetFortiManager Cloud7.6.2, 7.4.1, 7.2.1

Timeline

  • Sep 8, 2026 CVE Published
  • Sep 8, 2026 CVE Updated
  • Sep 9, 2026 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›