PT-2026-32667 · Fortinet · Fortisoar

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-22574

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiSOAR PaaS versions 7.6.0 through 7.6.4 FortiSOAR PaaS versions 7.5.0 through 7.5.2 FortiSOAR PaaS version 7.4 FortiSOAR PaaS version 7.3 FortiSOAR on-premise versions 7.6.0 through 7.6.4 FortiSOAR on-premise versions 7.5.0 through 7.5.2 FortiSOAR on-premise version 7.4 FortiSOAR on-premise version 7.3
Description An issue exists where passwords are stored in a recoverable format. This may allow an authenticated remote attacker to retrieve Service account passwords by modifying the server address in the LDAP configuration, potentially compromising the confidentiality of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2026-05553
CVE-2026-22574

Affected Products

Fortisoar