CVE-2023-25605: Fortinet Fortisoar

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.

Affected products

  • Fortinet Fortisoar: from 7.3.0, before 7.3.2 (fixed in 7.3.2)

Published 2023-03-07. Last modified 2026-06-17.