CVE-2026-22155: High severity Fortinet FortiSOAR PaaS vulnerability
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to information disclosure via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSOAR PaaSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.5.2 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
Fortinet FortiSOAR PaaSto a version that resolves this vulnerability.Fixed in 7.5.3 - Upgrade
Upgrade
Fortinet FortiSOAR on-premiseto a version that resolves this vulnerability.Fixed in 7.5.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22155?
CVE-2026-22155 has a medium severity due to the potential exposure of sensitive information through cleartext transmission.
How do I fix CVE-2026-22155?
To fix CVE-2026-22155, upgrade to Fortinet FortiSOAR PaaS version 7.6.4 or later, or 7.5.3 or later for the on-premise versions.
Which versions are affected by CVE-2026-22155?
CVE-2026-22155 affects Fortinet FortiSOAR PaaS versions 7.6.0 to 7.6.3, 7.5.0 to 7.5.2, as well as all versions of 7.4 and 7.3, and relevant on-premise versions.
What kind of information is exposed in CVE-2026-22155?
CVE-2026-22155 exposes sensitive information due to cleartext transmission, making it susceptible to interception during transit.
Is there a workaround for CVE-2026-22155?
Currently, there is no known workaround for CVE-2026-22155, and the recommended action is to apply the appropriate software updates.