Home

Description

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured

PUBLISHED Reserved 2026-01-05 | Published 2026-04-14 | Updated 2026-04-14 | Assigner fortinet




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

Problem types

Information disclosure

Product status

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-26-106

cve.org (CVE-2026-21742)

nvd.nist.gov (CVE-2026-21742)

Download JSON