CVE-2026-22575: Medium severity Fortinet FortiManager vulnerability
An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.11 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.11 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs administrator-level privileges on an affected FortiManager or FortiManager Cloud instance. The attack is performed by sending crafted HTTP or HTTPS requests.
What is the impact of successful exploitation?
A successful attacker can bypass the approval process for workflow sessions. The provided information identifies integrity impact, with no stated confidentiality or availability impact.
Which deployments are affected?
Affected releases are FortiManager 7.6.0 through 7.6.4, 7.4.0 through 7.4.10, and all 7.2 versions. FortiManager Cloud is affected in 7.6.2 through 7.6.4, 7.4.1 through 7.4.10, and all 7.2 versions.