Impact
A vulnerability of type improper access control (CWE‑284) exists in Fortinet FortiSOAR PaaS and on‑premise deployments. It allows an attacker that can exploit the flaw to gain higher privileges than intended, potentially escalating to system‑wide control. The weakness permits unauthorized escalation, exposing the security perimeter of affected installations.
Affected Systems
Fortinet FortiSOAR PaaS versions 7.3.x through 7.6.6, 7.5.x, 7.4.x, and 7.3.x are affected, as are FortiSOAR on‑premise releases 7.3.x to 7.6.6, 7.5.x, and 7.4.x. The specific vulnerable builds range from 7.3.0 to 7.6.6 for both PaaS and on‑premise platforms.
Risk and Exploitability
The CVSS base score of 4.9 indicates a moderate impact, and no EPSS data is available. The vulnerability is not listed in the CISA KEV database, suggesting no confirmed exploits. Because the attack vector is not explicitly defined, it is reasonable to assume that the issue requires authenticated access or is exploitable from a network context that permits interaction with FortiSOAR APIs. Overall, the risk remains moderate, but remediation is recommended to prevent potential privilege escalation.
OpenCVE Enrichment