CVE-2025-59808: Medium severity Fortinet FortiSOAR PaaS vulnerability
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59808?
CVE-2025-59808 is classified as a medium severity vulnerability affecting Fortinet FortiSOAR products.
How do I fix CVE-2025-59808?
To mitigate CVE-2025-59808, users should update FortiSOAR to the latest version available after patching is released.
What products are affected by CVE-2025-59808?
CVE-2025-59808 affects Fortinet FortiSOAR PaaS versions 7.3 to 7.6.2 and FortiSOAR on-premise versions 7.3 to 7.6.2.
What is the impact of CVE-2025-59808?
The impact of CVE-2025-59808 could allow an unverified password change, potentially compromising user accounts.
Is there a workaround for CVE-2025-59808?
Currently, no official workarounds are suggested for CVE-2025-59808, making prompt updates critical.