Executive brief
Fortinet FortiSOAR, a platform used for automating security operations and incident response, contains a vulnerability that exposes sensitive passwords. An authenticated user could view cleartext passwords for Secure Message Exchange and Radius services in system responses. This could allow an attacker with low-level access to escalate their privileges or gain unauthorized access to other connected network services.
Technical details
A Cleartext Transmission of Sensitive Information vulnerability (CWE-319) exists in the FortiSOAR GUI and API endpoints. The flaw is triggered when the system returns cleartext passwords in responses to queries related to Secure Message Exchange and Radius configurations. An authenticated attacker with network access can exploit this by intercepting or viewing these responses, leading to the disclosure of sensitive credentials. The vulnerability affects both PaaS and on-premise deployments across versions 7.3 through 7.6. Users are advised to upgrade to versions 7.6.4, 7.5.3, or other fixed releases as specified by the vendor.
Affected products
- Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, 7.5.0 through 7.5.2, 7.4 all versions, 7.3 all versions
- Fortinet FortiSOAR on-premise 7.6.0 through 7.6.2, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions
Timeline
- 2026-04-14: advisory: Initial publication by Fortinet
- 2026-04-14: disclosed