ZTNA Portal Improper Certificate Validation
FG-IR-26-174
CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.