FORTINET Security Advisory

Published Date: ๐Ÿ—“๏ธ : September 8, 2026

Advisory Summary

Title: โ›” Broken Access control on Websocket streams (FortiSOAR)

โœ… CVSSv3: 4.9 (Moderate)
Revised: 2026-09-08

For SOC operations and SOAR-driven response chains, unauthorized stream access can have outsize business impact, especially where event ingestion directly drives case creation, automation, or escalation.

### ๐Ÿšจ Practical risk scenario
An attacker who already has any valid FortiSOAR authentication (even with no assigned permissions) could attempt to:
1. Connect to the WebSocket endpoint
2. Enumerate/subscribe to streams and topics
3. Push crafted broadcast payloads to influence what other components receive

Consider testing adjacent endpoints for similar access control enforcement issues.

### โœ… Reference

Reference: Vendor Advisory