CVE-2025-59808: Fortinet Fortisoar
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password
Affected products
- Fortinet Fortisoar: from 7.3.0, before 7.5.2 (fixed in 7.5.2); from 7.6.0, up to and including 7.6.3
Published 2025-12-09. Last modified 2026-06-17.