Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-22256

CVE-2025-22256: Fortinet FortiPAM Auth Bypass Vulnerability

CVE-2025-22256 is an authentication bypass flaw in Fortinet FortiPAM that enables attackers to circumvent access controls through crafted HTTP requests. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-22256 Overview

CVE-2025-22256 is an improper access control vulnerability affecting Fortinet FortiPAM and FortiSRA appliances. The flaw stems from improper handling of insufficient permissions or privileges [CWE-280]. An authenticated attacker can send specially crafted HTTP requests to bypass access control restrictions on the management interface. Successful exploitation allows attackers to perform actions outside their assigned privilege level, compromising the confidentiality, integrity, and availability of managed credentials and privileged sessions.

Critical Impact

An authenticated attacker with low privileges can escalate access through crafted HTTP requests and reach resources protected by FortiPAM and FortiSRA, including stored privileged credentials.

Affected Products

  • Fortinet FortiPAM versions 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, 1.2.0, 1.3.0, and 1.4.0 through 1.4.1
  • Fortinet FortiSRA versions 1.4.0 through 1.4.1
  • Privileged Access Management and Secure Remote Access deployments using the above releases

Discovery Timeline

  • 2025-06-10 - CVE-2025-22256 published to the National Vulnerability Database
  • 2025-07-24 - Last updated in NVD database

Technical Details for CVE-2025-22256

Vulnerability Analysis

The vulnerability is classified under [CWE-280] Improper Handling of Insufficient Permissions or Privileges. FortiPAM and FortiSRA fail to consistently enforce permission checks when processing specific HTTP request paths or parameters. An attacker holding a low-privilege account can issue crafted requests that bypass the authorization layer and reach functionality reserved for higher-privilege roles.

Because FortiPAM brokers access to privileged credentials and FortiSRA mediates remote administrative sessions, broken access control on these products has outsized downstream impact. An attacker exploiting this flaw could read or modify vault entries, alter session policies, or pivot into managed infrastructure using stored secrets.

Root Cause

The root cause is a missing or insufficient privilege check on protected API endpoints. The application validates that the requester is authenticated but does not consistently verify that the authenticated principal holds the role required for the requested operation. This authorization gap exists across multiple FortiPAM release branches, indicating a long-standing logic defect rather than a regression.

Attack Vector

Exploitation requires network access to the FortiPAM or FortiSRA management interface and valid low-privilege credentials. The attacker crafts HTTP requests targeting endpoints normally restricted to administrators or higher-tier operators. No user interaction is required, and the attack can be conducted entirely over the network. Refer to the Fortinet Security Advisory FG-IR-25-008 for endpoint-specific technical details.

Detection Methods for CVE-2025-22256

Indicators of Compromise

  • Unexpected administrative actions, vault reads, or policy changes originating from accounts assigned non-administrative roles
  • HTTP requests from low-privilege users targeting administrative API paths on the FortiPAM or FortiSRA management interface
  • New or modified secret retrievals followed by remote session initiations to managed assets within a short window

Detection Strategies

  • Correlate authenticated session role with the sensitivity of the API endpoints invoked, flagging mismatches
  • Baseline normal per-role HTTP request patterns and alert on deviations such as low-tier operators accessing vault, user management, or policy endpoints
  • Review FortiPAM and FortiSRA audit logs for permission-denied entries immediately followed by successful equivalent operations

Monitoring Recommendations

  • Forward FortiPAM and FortiSRA application and audit logs to a centralized SIEM or data lake for cross-account analysis
  • Monitor for credential checkouts initiated by service or low-privilege accounts that have no operational reason to access target systems
  • Track outbound sessions from FortiSRA to managed endpoints and alert on first-seen user-to-asset combinations

How to Mitigate CVE-2025-22256

Immediate Actions Required

  • Upgrade FortiPAM and FortiSRA to the fixed releases listed in Fortinet Security Advisory FG-IR-25-008
  • Restrict management interface exposure to trusted administrative networks only
  • Audit existing FortiPAM and FortiSRA user accounts and remove unused or excessive privileges
  • Rotate any privileged credentials stored in FortiPAM if unauthorized access cannot be ruled out

Patch Information

Fortinet has released patched versions for the affected FortiPAM 1.0, 1.1, 1.2, 1.3, and 1.4 branches, and for FortiSRA 1.4. Administrators should consult the Fortinet PSIRT advisory FG-IR-25-008 for the specific fixed build numbers corresponding to their deployed branch and apply them as soon as practical.

Workarounds

  • Limit access to the FortiPAM and FortiSRA web and API interfaces using firewall rules or trusted host configurations
  • Enforce multi-factor authentication for all FortiPAM and FortiSRA accounts to raise the cost of low-privilege credential abuse
  • Temporarily disable or disable login for non-administrative accounts that are not actively required until patches are applied
bash
# Example: restrict FortiPAM admin access to a trusted management subnet
config system admin
    edit "operator1"
        set trusthost1 10.10.0.0 255.255.255.0
        set accprofile "read_only"
    next
end

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.