PT-2026-32664 · Fortinet · Fortisoar

Michele Spagnuolo

·

Published

2026-04-14

·

Updated

2026-05-06

·

CVE-2026-22154

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiSOAR PaaS versions 7.6.0 through 7.6.3 FortiSOAR PaaS versions 7.5.0 through 7.5.2 FortiSOAR PaaS versions 7.4 FortiSOAR PaaS versions 7.3 FortiSOAR on-premise versions 7.6.0 through 7.6.3 FortiSOAR on-premise versions 7.5.0 through 7.5.2 FortiSOAR on-premise versions 7.4 FortiSOAR on-premise versions 7.3
Description An improper neutralization of input during web page generation allows an authenticated remote attacker to perform a stored cross-site scripting (XSS) attack via crafted HTTP Requests. XSS is a flaw where malicious scripts are injected into otherwise benign and trusted websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05559
CVE-2026-22154

Affected Products

Fortisoar