Fortinet FortiManager Vulnerability Allows Workflow Approval Bypass
A critical access control flaw in Fortinet's FortiManager allows administrators to bypass workflow session approvals through crafted HTTP requests.

Fortinet's Product Security Incident Response Team (PSIRT) has disclosed an improper access control vulnerability, identified as CWE-284, affecting its FortiManager product. This security flaw, detailed in advisory FG-IR-26-171, permits an administrator to circumvent the established approval process for workflow sessions.
The vulnerability is exploitable by an administrator who can craft specific HTTP or HTTPS requests. By manipulating these requests, an attacker with administrative privileges can bypass the intended multi-step approval workflow, potentially leading to unauthorized changes or actions being committed without proper oversight. This bypass mechanism undermines the integrity of the workflow management system, which is designed to ensure accountability and control over critical administrative tasks.
The CVSSv3 score for this vulnerability is rated at 4.7, classifying it as medium severity. While not reaching the critical threshold, a CVSS score of 4.7 indicates a notable risk, especially in environments where FortiManager is used for managing critical network infrastructure or sensitive configurations. The impact could range from minor policy misconfigurations to more significant operational disruptions, depending on the specific workflows being bypassed.
FortiManager is a centralized management solution for Fortinet's FortiGate firewalls and other security products. It enables organizations to manage large deployments of security devices efficiently, including policy updates, firmware management, and configuration changes. The workflow approval process is a key feature designed to prevent accidental or malicious changes by requiring review and explicit approval from designated personnel before changes are implemented.
Exploitation of this vulnerability requires an attacker to already possess administrative credentials for the FortiManager system. This means the threat is primarily internal or targets an attacker who has already achieved a significant level of compromise within the network. However, the ease with which the bypass can be achieved through crafted requests suggests that once an attacker gains administrative access, they can operate with a reduced risk of detection through standard workflow monitoring.
Fortinet has released updates to address this vulnerability. Users of FortiManager are strongly advised to consult the official Fortinet PSIRT advisory (FG-IR-26-171) for detailed information on affected versions and the necessary steps to remediate the issue. Applying the latest patches and security configurations is crucial to mitigate the risk of unauthorized workflow modifications.
This incident underscores the importance of robust access control and the need for continuous monitoring of administrative actions, even within trusted internal systems. Organizations relying on FortiManager should ensure their administrative access controls are strictly enforced and that all security updates are applied promptly to protect against potential exploitation.