PT-2026-32668 · Fortinet · Fortisoar

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-22576

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiSOAR PaaS versions 7.6.0 through 7.6.4 FortiSOAR PaaS versions 7.5.0 through 7.5.2 FortiSOAR PaaS version 7.4 FortiSOAR PaaS version 7.3 FortiSOAR on-premise versions 7.6.0 through 7.6.4 FortiSOAR on-premise versions 7.5.0 through 7.5.2 FortiSOAR on-premise version 7.4 FortiSOAR on-premise version 7.3
Description An issue exists where passwords are stored in a recoverable format. An authenticated remote attacker can retrieve passwords for multiple installed connectors by modifying the server address within the connector configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2026-05565
CVE-2026-22576

Affected Products

Fortisoar