CVE-2022-38375: Fortinet Fortinac

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

Affected products

  • Fortinet Fortinac: from 9.2.0, before 9.2.7 (fixed in 9.2.7); from 9.4.0, before 9.4.2 (fixed in 9.4.2)
  • Fortinet Fortinac-F: before 7.2.0 (fixed in 7.2.0)

Published 2023-02-16. Last modified 2026-06-17.