SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-22575

MEDIUM · CVSS 4.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An improper access control vulnerability in multiple versions of Fortinet FortiManager and FortiManager Cloud allows an attacker to bypass the approval process for workflow sessions through specially crafted HTTP or HTTPS requests. This could lead to unauthorized actions being performed within the management interface, potentially compromising the integrity of network configurations. Organizations using affected Fortinet products, particularly those with administrative access, should prioritize patching to mitigate this risk.

CVE
CVE-2026-22575
Severity
MEDIUM
CVSS
4.9
EPSS
0.24%
Fortinet

Original NVD Description

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.