FortiSOAR PaaS Vulnerability

MEDIUM (6.5) Patch Available

Threat Intelligence

Low Risk
EPSS Score: 0.04% chance of exploitation (percentile: 12%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

FortiSOAR is a cloud-based platform for managing and automating security operations. This vulnerability allows an authenticated attacker to access sensitive information by crafting malicious requests. The risk is significant as it can lead to unauthorized disclosure of employee data, payroll records, and system configurations.

Am I affected?

You're affected if you use An improper access control vulnerability. Affected versions: 7.5.1, 7.6.2 If you don't recognise this software, you're probably not affected.

Affected Products

Fortinet / FortiSOAR PaaS

How to fix

To fix this vulnerability, upgrade to the following fixed versions:
- FortiSOAR PaaS: 7.6.3 or above (available on the Fortinet website)
- Immediate mitigations:
- Restrict network access to your FortiSOAR instance (firewall it from the public internet)
- Audit admin account activity for suspicious access patterns
- Monitor for unauthorized token creation

References