CVE-2026-21742: Medium severity Fortinet FortiSOAR PaaS vulnerability
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSOAR PaaSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.5.2 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
Fortinet FortiSOAR PaaSto a version that resolves this vulnerability.Fixed in 7.5.3 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.5.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21742?
The severity of CVE-2026-21742 is classified as a medium risk due to cleartext transmission of sensitive information.
How do I fix CVE-2026-21742?
To fix CVE-2026-21742, ensure to update Fortinet FortiSOAR PaaS to version 7.6.4 or later and FortiSOAR on-premise to version 7.6.3 or later.
What systems are affected by CVE-2026-21742?
CVE-2026-21742 affects Fortinet FortiSOAR PaaS versions 7.6.0 to 7.6.3, 7.5.0 to 7.5.2, and all versions of 7.4 and 7.3, as well as on-premise versions of 7.6.0 to 7.6.2 and 7.5.0 to 7.5.1.
What type of data is exposed in CVE-2026-21742?
CVE-2026-21742 exposes sensitive information due to cleartext transmission, potentially allowing interception by attackers.
Is there a workaround for CVE-2026-21742?
Currently, the recommended action for CVE-2026-21742 is to upgrade to the latest secure versions rather than relying on a workaround.