CVE-2026-22154: XSS
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP Requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22154?
CVE-2026-22154 is considered a high severity vulnerability due to its potential for enabling cross-site scripting attacks.
How do I fix CVE-2026-22154?
To mitigate CVE-2026-22154, you should upgrade to a patched version of Fortinet FortiSOAR PaaS or FortiSOAR on-premise that addresses this vulnerability.
What versions are affected by CVE-2026-22154?
CVE-2026-22154 affects Fortinet FortiSOAR PaaS versions from 7.3.0 up to 7.6.3 and FortiSOAR on-premise from 7.3.0 to 7.6.3.
What types of attacks could CVE-2026-22154 lead to?
CVE-2026-22154 could lead to cross-site scripting attacks, allowing an attacker to inject malicious scripts into web pages viewed by users.
Is there a workaround for CVE-2026-22154?
Currently, the best course of action for CVE-2026-22154 is to apply the available security updates rather than relying on workarounds.