SB2026041514 - Multiple vulnerabilities in FortiSOAR
Published: April 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-22155)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in response for API endpoints. An authenticated attacker can view cleartext password in response for Secure Message Exchange and Radius queries, if configured.
2) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-21742)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in response for API endpoints. An authenticated attacker can view cleartext password in response for Secure Message Exchange and Radius queries, if configured.
Remediation
Install update from vendor's website.