> Broken Access control on Websocket streams
[DATE: 08/09/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
4.9
An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests
Revised on 2026-09-08 00:00:00