PT-2026-32665 · Fortinet · Fortisoar

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-22155

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiSOAR PaaS versions 7.6.0 through 7.6.3 FortiSOAR PaaS versions 7.5.0 through 7.5.2 FortiSOAR PaaS version 7.4 FortiSOAR PaaS version 7.3 FortiSOAR on-premise versions 7.6.0 through 7.6.2 FortiSOAR on-premise versions 7.5.0 through 7.5.1 FortiSOAR on-premise version 7.4 FortiSOAR on-premise version 7.3
Description A cleartext transmission of sensitive information issue exists in the graphical user interface of the cybersecurity orchestration and real-time incident response management software. This flaw may allow a remote attacker to gain unauthorized access to protected information through information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2026-05560
CVE-2026-22155

Affected Products

Fortisoar