Unverified Password Change Vulnerability in Fortinet FortiSOAR PaaS
CVE-2025-59808
6.5MEDIUM
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-59808?
A security vulnerability in Fortinet FortiSOAR PaaS allows an attacker with access to a victim's user account to reset credentials without proper authorization. This flaw affects multiple versions of FortiSOAR, facilitating unauthorized access and compromising account security by bypassing password verification processes. Users are urged to review and update to the latest secure versions to mitigate risk.
Affected Version(s)
FortiSOAR on-premise 7.6.0 <= 7.6.2
FortiSOAR on-premise 7.5.0 <= 7.5.1
FortiSOAR on-premise 7.4.0 <= 7.4.5