Unverified Password Change Vulnerability in Fortinet FortiSOAR PaaS
CVE-2025-59808

6.5MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
9 December 2025

What is CVE-2025-59808?

A security vulnerability in Fortinet FortiSOAR PaaS allows an attacker with access to a victim's user account to reset credentials without proper authorization. This flaw affects multiple versions of FortiSOAR, facilitating unauthorized access and compromising account security by bypassing password verification processes. Users are urged to review and update to the latest secure versions to mitigate risk.

Affected Version(s)

FortiSOAR on-premise 7.6.0 <= 7.6.2

FortiSOAR on-premise 7.5.0 <= 7.5.1

FortiSOAR on-premise 7.4.0 <= 7.4.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.