---
id: CVE-2026-22575
title: >-
  An improper access control vulnerability in Fortinet FortiManager 7.6.0
  through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all
  versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1
  through 7.4.10, For…
summary: >-
  An improper access control vulnerability in Fortinet FortiManager 7.6.0
  through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all
  versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1
  through 7.4.10, For…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
vendor: Fortinet
product: FortiManager
affected:
  - FortiManager >= 7.6.0 <= 7.6.4
  - FortiManager >= 7.4.0 <= 7.4.10
  - FortiManager >= 7.2.0 <= 7.2.12
  - FortiManager >= 7.0.0 <= 7.0.16
  - FortiManager >= 6.4.0 <= 6.4.15
  - fortimanager_cloud >= 7.6.2 <= 7.6.4
  - fortimanager_cloud >= 7.4.1 <= 7.4.10
  - fortimanager_cloud >= 7.2.1 <= 7.2.12
  - fortimanager_cloud >= 7.0.1 <= 7.0.16
  - fortimanager_cloud >= 6.4.1 <= 6.4.7
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T18:35:10.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22575'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-171'
    label: psirt@fortinet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:28:52.915929Z'
scores:
  nvd: 4.9
  cna: 4.7
ingestedAt: '2026-09-08T17:06:31.890Z'
epss: 0.00245
epssPercentile: 0.1392
---

## Overview

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
