CVE-2026-22576: Medium severity Fortinet FortiSOAR PaaS vulnerability
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22576?
CVE-2026-22576 is rated as a high severity vulnerability due to the risks associated with storing passwords in a recoverable format.
How do I fix CVE-2026-22576?
To mitigate CVE-2026-22576, update to the latest versions of Fortinet FortiSOAR PaaS or FortiSOAR on-premise that have addressed this vulnerability.
What products are affected by CVE-2026-22576?
CVE-2026-22576 affects multiple versions of Fortinet FortiSOAR PaaS and on-premise variants from 7.3 to 7.6.4.
What type of vulnerability is CVE-2026-22576?
CVE-2026-22576 is a vulnerability related to the improper storage of passwords in a recoverable format.
Is there a workaround for CVE-2026-22576?
No specific workaround is provided; the recommended solution is to update to the patched versions.