Junglewise Threat Intelligence

CVE-2026-84385: Fortinet FortiSOAR improper access control in WebSocket streams

CVE-2026-84385 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Technologies: Fortinet FortiSOAR PaaS, Fortinet Fortisoar. Vendors: Fortinet.

Executive brief

FortiSOAR is a security orchestration and incident response platform used by enterprises to automate security operations. An improper access control vulnerability allows authenticated users with minimal permissions to subscribe to restricted WebSocket data streams and inject false messages into the system, potentially enabling privilege escalation and data manipulation within security operations workflows.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in FortiSOAR's WebSocket stream handler that fails to properly validate user permissions before allowing subscription to protected topics and message broadcast injection. An authenticated attacker with zero permissions can craft malicious WebSocket requests to bypass access restrictions, subscribe to sensitive security event streams, and inject broadcast messages to manipulate incident response workflows. The vulnerability requires valid authentication but does not require elevated privileges. Fortinet has released patches for affected versions: 7.6.7+, 7.5.4+; versions 7.3 and 7.4 require migration to a fixed release.

Affected products

  • Fortinet FortiSOAR PaaS 7.3 all versions, 7.4 all versions, 7.5.0 through 7.5.3, 7.6.0 through 7.6.6
  • Fortinet FortiSOAR 7.3 all versions, 7.4 all versions, 7.5.0 through 7.5.3, 7.6.0 through 7.6.6

Timeline

  • 2026-09-08: disclosed

References

Related threats