ZeroHour
Fortinet PSIRTpublished ()ingested

Workflow session email approval process bypass

mediumAdvisoryimportance 15
AI summary · glm-5.3

Fortinet disclosed an improper access control flaw (CVSS 4.7) in FortiManager allowing administrators to bypass workflow session email approval via crafted HTTP requests.

Fortinet advisory FG-IR-26-171 covers an improper access control vulnerability (CWE-284) in FortiManager, rated CVSSv3 4.7. An administrator can bypass the approval process for workflow sessions via crafted HTTP or HTTPS requests. The advisory was revised on 2026-09-08.

  • CVSSv3 4.7 improper access control (CWE-284) in FortiManager
  • Administrator can bypass workflow session approval process
  • Exploited via crafted HTTP or HTTPS requests
Full article

CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.