PT-2025-50120 · Fortinet · Fortisoar Paas+1

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2025-59808

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiSOAR PaaS versions 7.3 through 7.6.2 Fortinet FortiSOAR on-premise versions 7.3 through 7.6.2
Description An unverified password change issue exists that may allow an attacker with existing access to a user account to reset the account credentials without providing the current password. The issue is related to a lack of proper verification during password reset operations.
Recommendations FortiSOAR PaaS versions 7.3 through 7.6.2 should be updated. FortiSOAR on-premise versions 7.3 through 7.6.2 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-59808

Affected Products

Fortisoar Paas
Fortisoar On-Premise