Executive brief
Fortinet FortiSOAR is a platform used by security teams to automate and manage incident responses. A vulnerability in this system could allow an authorized user to view sensitive passwords in plain text when the system communicates with external messaging or authentication services. This could lead to unauthorized access to other corporate systems or sensitive data.
Technical details
A cleartext transmission of sensitive information vulnerability (CWE-319) exists in Fortinet FortiSOAR (both PaaS and on-premise versions). The flaw is located within the GUI/API component where sensitive credentials, specifically passwords for Secure Message Exchange and RADIUS queries, are returned in unencrypted plain text within API responses. An authenticated attacker with network access to the API endpoints can exploit this to capture credentials if those services are configured. The vulnerability is addressed in FortiSOAR versions 7.6.4, 7.5.3, and later releases.
Affected products
- Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, 7.5.0 through 7.5.2, 7.4 all versions, 7.3 all versions
- Fortinet FortiSOAR on-premise 7.6.0 through 7.6.2, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory