Command Injection Vulnerability in Fortinet FortiDeceptor Products
CVE-2026-25690

4MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
12 May 2026

What is CVE-2026-25690?

An improper neutralization of argument delimiters vulnerability in Fortinet's FortiDeceptor products allows an authenticated attacker with read-only admin permissions to potentially access sensitive log files. This is executed through specially crafted HTTP requests, which could undermine the confidentiality of the affected systems.

Affected Version(s)

FortiDeceptor 6.0.0 <= 6.0.2

FortiDeceptor 5.3.0 <= 5.3.3

FortiDeceptor 5.2.0 <= 5.2.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.