Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Fortinet PSIRT

Broken Access control on Websocket streams

  • What: A broken access control vulnerability in FortiSOAR is disclosed
  • Impact: Authenticated attackers may gain unauthorized access to websocket streams
Read Full Article →

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

Share this article