Medium SEVERITY — Vulnerability

Broken Access control on Websocket streams

CVSSv3 Score: 4.9 An Improper Access control vulnerability in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
4.9/10
Advisory
FG-IR-26-164
Published
08 September 2026
Views
25
Primary source: Review the official advisory at fortiguard.fortinet.com Go to Source

Summary

CVSSv3 Score: 4.9 An Improper Access control vulnerability in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

Source

FortiGate / FortiOS — Related Advisories

VIEW ALL →