CVE-2026-22576

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all ve

Severity
Medium 4.1
CVSS 3.1
Exploited
Not listed
EPSS
0.003
18.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 14, 2026
Assigned by fortinet

Description

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration.

Weakness: CWE-257

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiSOAR PaaS
  • Fortinet · FortiSOAR on-premise

Credit

Internally discovered and reported by Shripal Rawal of Fortinet PSIRT team.

Vendor remediation

Upgrade to FortiSOAR on-premise version 7.6.5 or above Upgrade to upcoming FortiSOAR on-premise version 7.5.3 or above Upgrade to FortiSOAR PaaS version 7.6.5 or above Upgrade to upcoming FortiSOAR PaaS version 7.5.3 or above

Something wrong here?