VYPR
Unrated severityNVD Advisory· Published Oct 2, 2025· Updated Feb 26, 2026

CVE-2025-22862

CVE-2025-22862

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.

Affected products

4
  • Fortinet/Fortiproxyv52 versions
    cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiproxy:7.6.2:*:*:*:*:*:*:*range: 7.6.0
    • (no CPE)range: >=7.0.5, <=7.6.2 || >=7.2.0, <=7.2 all || >=7.4.0, <=7.4.8
  • Fortinet/Fortiosv52 versions
    cpe:2.3:o:fortinet:fortios:7.4.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:7.4.7:*:*:*:*:*:*:*range: 7.4.0
    • (no CPE)range: >=7.0.6, <=7.4.7 || >=7.2.0, <=7.2.11 || >=7.4.0, <=7.4.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.