ZeroHour
Fortinet PSIRTpublished ()ingested

Broken Access control on Websocket streams

lowAdvisoryimportance 16
AI summary · glm-5.3

Fortinet FortiSOAR access control flaw (CVSS 4.9) lets zero-permission authenticated attackers subscribe to and inject broadcast messages into websocket streams.

Fortinet advisory FG-IR-26-164 discloses an improper access control vulnerability (CWE-284, CVSSv3 4.9) in FortiSOAR. An authenticated attacker with zero permissions can subscribe to websocket streams and topics and inject broadcast messages via crafted websocket requests. The advisory was revised on 2026-09-08.

  • Improper access control (CWE-284) in FortiSOAR, CVSSv3 4.9
  • Zero-permission authenticated attacker can subscribe to websocket streams
  • Crafted websocket requests enable broadcast message injection
Full article

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.