Fortinet FortiSOAR Clear-Text Password Retrieval Vulnerability via LDAP Configuration Modification

Vulnerability

A vulnerability allowing passwords to be stored in a recoverable format has been identified in Fortinet FortiSOAR. This issue affects FortiSOAR PaaS versions 7.6.0 to 7.6.4, 7.5.0 to 7.5.2, and all versions of FortiSOAR PaaS 7.4 and 7.3, as well as FortiSOAR on-premise versions 7.6.0 to 7.6.4, 7.5.0 to 7.5.2, and all versions of 7.4 and 7.3. The vulnerability may allow an authenticated remote attacker to retrieve service account passwords by modifying the server address in the LDAP configuration.

Impact

Exploitation of this vulnerability could lead to unauthorized retrieval of service account passwords, allowing for potential misuse of those accounts.

Remediation

Users can upgrade to FortiSOAR PaaS 7.6.5 or 7.5.3, depending on their current version. FortiSOAR on-premise users should also upgrade to 7.6.5 or 7.5.3, or migrate to a fixed release if they are on FortiSOAR PaaS or on-premise versions 7.4 or 7.3.

Added: Apr 14, 2026, 5:38 PM
Updated: Apr 14, 2026, 5:38 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
6.3
remediation
7.7
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.