CVE-2026-22574CWE-257

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS…

Medium · published April 14, 2026

CVSS v3.1
4.1
EPSS
0%
Percentile
18.6
In the wild
Unconfirmed
What it is

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration.

The record
Technical detail
CVSS v3.1
4.1 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:H/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00267 · 18.6th percentile
Weakness
CWE-257 · Storing Passwords in a Recoverable Format
Published
2026-04-14T15:38Z
EPSS history
Timeline
  • 14 APR 15:38Z
    A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS…
    cvelistv5