Access Control Bypass in Fortinet FortiManager Products
CVE-2026-22575
4.7MEDIUM
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-22575?
An improper access control vulnerability exists in Fortinet FortiManager, affecting various versions. This flaw may enable an attacker with administrative privileges to bypass the approval requirements for workflow sessions via specially crafted HTTP or HTTPS requests. The affected products span multiple versions, raising concerns about potential unauthorized actions within the management interface.
Affected Version(s)
FortiManager 7.6.0 <= 7.6.4
FortiManager 7.4.0 <= 7.4.10
FortiManager 7.2.0 <= 7.2.12