Command Injection Vulnerability in Fortinet FortiDeceptor Products
CVE-2026-25690
4MEDIUM
What is CVE-2026-25690?
An improper neutralization of argument delimiters vulnerability in Fortinet's FortiDeceptor products allows an authenticated attacker with read-only admin permissions to potentially access sensitive log files. This is executed through specially crafted HTTP requests, which could undermine the confidentiality of the affected systems.
Affected Version(s)
FortiDeceptor 6.0.0 <= 6.0.2
FortiDeceptor 5.3.0 <= 5.3.3
FortiDeceptor 5.2.0 <= 5.2.1