CVE-2025-22256: Fortinet Fortipam

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests

Affected products

  • Fortinet Fortipam: from 1.0.0, before 1.0.4 (fixed in 1.0.4); from 1.1.0, before 1.1.3 (fixed in 1.1.3); from 1.4.0, before 1.4.2 (fixed in 1.4.2); version 1.2.0 only; version 1.3.0 only
  • Fortinet Fortisra: from 1.4.0, before 1.4.2 (fixed in 1.4.2)

Published 2025-06-10. Last modified 2026-06-17.