Executive brief
FortiManager is a centralized management platform used by organizations to administer Fortinet security devices and policies. An authenticated administrator could craft malicious requests to bypass the workflow approval process, allowing unauthorized changes to propagate without proper authorization checks. This undermines operational governance and can lead to unintended policy modifications across managed devices.
Technical details
This is an improper access control vulnerability (CWE-284) in the GUI component of FortiManager that affects the workflow session email approval process. An authenticated administrator can submit crafted HTTP/HTTPS requests to bypass the approval workflow, circumventing the authorization controls designed to enforce change management policies. The vulnerability requires authentication and direct network access to the FortiManager instance. An attacker with administrative credentials can approve their own workflow sessions without waiting for a separate approver's authorization, or bypass approval requirements entirely. Patches are available: FortiManager 7.6.5+, 7.4.11+; older versions (7.2) require migration to a fixed release. FortiManager 8.0 is not affected.
Affected products
- Fortinet FortiManager 7.6.0 through 7.6.4, 7.4.0 through 7.4.10, 7.2 all versions
- Fortinet FortiManager Cloud 7.6.2 through 7.6.4, 7.4.1 through 7.4.10, 7.2 all versions
Timeline
- 2026-09-08: disclosed