CVE-2026-22574
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:H/RL:O/RC:C
- EPSS probability
- 0.27%
- CWE
- CWE-257
- Published
- 2026-04-14
- Last modified
- 2026-04-14
Affected products
- Fortinet FortiSOAR PaaS
- Fortinet FortiSOAR PaaS
- Fortinet FortiSOAR PaaS
- Fortinet FortiSOAR PaaS
- Fortinet FortiSOAR on-premise
- Fortinet FortiSOAR on-premise
- Fortinet FortiSOAR on-premise
- Fortinet FortiSOAR on-premise
Weakness type
Related vulnerabilities
- CVE-2026-69297 — Windows DHCP Server Information Disclosure Vulnerability
- CVE-2026-80176 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-65309 — Storage of passwords in a reversible format
- CVE-2026-1836 — Stored credentials in Redmine
- CVE-2026-22576 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through...
- CVE-2025-8095 — Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
- CVE-2016-15058 — Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
- CVE-2026-22614 — The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to...