Impact
An improper access control flaw in FortiManager and FortiManager Cloud allows an authenticated administrator to craft HTTP or HTTPS requests that circumvent the required approval step for workflow sessions. This bypass can enable privileged operations—such as modifying device configurations or deploying policies—without the standard authorization, aligning with CWE‑284 access control weaknesses.
Affected Systems
Affected are FortiManager versions 7.6.0‑7.6.4, 7.4.0‑7.4.10, and all 7.2 releases, as well as FortiManager Cloud versions 7.6.2‑7.6.4, 7.4.1‑7.4.10, and all 7.2 releases. Fortinet recommends upgrading to FortiManager 8.0.0 or at least 7.6.5, and to FortiManager Cloud 8.0.0 or at least 7.6.5, to address this issue.
Risk and Exploitability
The CVSS score of 4.7 classifies the vulnerability as medium severity. No EPSS score is publicly available and it is not listed in the CISA KEV catalog, suggesting limited active exploitation evidence. The attack vector appears to require network access to the administrative HTTP/HTTPS interfaces and an authenticated administrator account, permitting unauthorized configuration changes within the scope of that administrator within compromised devices.
OpenCVE Enrichment