Current password requirement bypass for self password change

Summary

An Unverified Password Change vulnerability [CWE-620] in FortiSOAR may allow an attacker who gained access to a victim's user account to reset the account credentials without being prompted for the account's password

Version Affected Solution
FortiSOAR PaaS 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiSOAR PaaS 7.5 7.5.0 through 7.5.1 Upgrade to 7.5.2 or above
FortiSOAR PaaS 7.4 7.4 all versions Migrate to a fixed release
FortiSOAR PaaS 7.3 7.3 all versions Migrate to a fixed release
FortiSOAR on-premise 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiSOAR on-premise 7.5 7.5.0 through 7.5.1 Upgrade to 7.5.2 or above
FortiSOAR on-premise 7.4 7.4 all versions Migrate to a fixed release
FortiSOAR on-premise 7.3 7.3 all versions Migrate to a fixed release
FortiSOAR on-premise 7.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Shripal Rawal of Fortinet PSIRT team.

Timeline

2025-12-09: Initial publication