Junglewise Threat Intelligence

CVE-2026-22575: Fortinet FortiManager improper access control in workflow approval

CVE-2026-22575 · Severity: medium · CVSS 4.9 · Published 2026-09-08

Technologies: Fortinet FortiManager. Vendors: Fortinet.

Executive brief

FortiManager is a centralized management platform used by organizations to administer Fortinet security devices and policies. An authenticated administrator could craft malicious requests to bypass the workflow approval process, allowing unauthorized changes to propagate without proper authorization checks. This undermines operational governance and can lead to unintended policy modifications across managed devices.

Technical details

This is an improper access control vulnerability (CWE-284) in the GUI component of FortiManager that affects the workflow session email approval process. An authenticated administrator can submit crafted HTTP/HTTPS requests to bypass the approval workflow, circumventing the authorization controls designed to enforce change management policies. The vulnerability requires authentication and direct network access to the FortiManager instance. An attacker with administrative credentials can approve their own workflow sessions without waiting for a separate approver's authorization, or bypass approval requirements entirely. Patches are available: FortiManager 7.6.5+, 7.4.11+; older versions (7.2) require migration to a fixed release. FortiManager 8.0 is not affected.

Affected products

  • Fortinet FortiManager 7.6.0 through 7.6.4, 7.4.0 through 7.4.10, 7.2 all versions
  • Fortinet FortiManager Cloud 7.6.2 through 7.6.4, 7.4.1 through 7.4.10, 7.2 all versions

Timeline

  • 2026-09-08: disclosed

References

Related threats