Workflow session email approval process bypass
AI summary · glm-5.3
Fortinet disclosed an improper access control flaw (CVSS 4.7) in FortiManager allowing administrators to bypass workflow session email approval via crafted HTTP requests.
Fortinet advisory FG-IR-26-171 covers an improper access control vulnerability (CWE-284) in FortiManager, rated CVSSv3 4.7. An administrator can bypass the approval process for workflow sessions via crafted HTTP or HTTPS requests. The advisory was revised on 2026-09-08.
- CVSSv3 4.7 improper access control (CWE-284) in FortiManager
- Administrator can bypass workflow session approval process
- Exploited via crafted HTTP or HTTPS requests
Full article
CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.