Executive brief
FortiSOAR is a security orchestration and incident response platform used by enterprises to automate security operations. An improper access control vulnerability allows authenticated users with minimal permissions to subscribe to restricted WebSocket data streams and inject false messages into the system, potentially enabling privilege escalation and data manipulation within security operations workflows.
Technical details
The vulnerability is an improper access control flaw (CWE-284) in FortiSOAR's WebSocket stream handler that fails to properly validate user permissions before allowing subscription to protected topics and message broadcast injection. An authenticated attacker with zero permissions can craft malicious WebSocket requests to bypass access restrictions, subscribe to sensitive security event streams, and inject broadcast messages to manipulate incident response workflows. The vulnerability requires valid authentication but does not require elevated privileges. Fortinet has released patches for affected versions: 7.6.7+, 7.5.4+; versions 7.3 and 7.4 require migration to a fixed release.
Affected products
- Fortinet FortiSOAR PaaS 7.3 all versions, 7.4 all versions, 7.5.0 through 7.5.3, 7.6.0 through 7.6.6
- Fortinet FortiSOAR 7.3 all versions, 7.4 all versions, 7.5.0 through 7.5.3, 7.6.0 through 7.6.6
Timeline
- 2026-09-08: disclosed