Junglewise Threat Intelligence

CVE-2025-22862: Fortinet FortiOS and FortiProxy privilege escalation in Automation Stitch

CVE-2025-22862 · Severity: medium · CVSS 6.7 · Published 2025-10-02

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

FortiOS and FortiProxy are operating systems used to manage network security and web traffic filtering. A security flaw in the 'Automation Stitch' feature could allow a user who already has high-level access to bypass security checks and further increase their control over the system. This could lead to unauthorized changes to security policies or full administrative takeover of the device.

Technical details

An Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) exists in the Automation Stitch component of FortiOS and FortiProxy. The flaw is triggered via a malicious Webhook action within the automation framework. An authenticated attacker with high privileges (PR:H) can exploit this to bypass standard authentication paths and achieve further privilege escalation. The vulnerability is accessible locally or via the management interface. Fortinet has released patches for affected versions, including FortiOS 7.4.8, 7.2.12, and FortiProxy 7.6.3 and 7.4.9.

Affected products

  • Fortinet FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above
  • Fortinet FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above

Timeline

  • 2025-06-10: disclosed: Initial publication by Fortinet
  • 2025-09-15: patched: Added FortiOS 7.2.12 solution
  • 2025-10-02: advisory: NVD publication date

References

Related threats