SB2026090971 - Improper access control in FortiManager



SB2026090971 - Improper access control in FortiManager

Published: September 9, 2026

Security Bulletin ID SB2026090971
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-22575)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to manipulate data.

The vulnerability exists due to improper access control. An administrator can bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.


Remediation

Install update from vendor's website.