CVE-2026-25690

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:5.2.1:*:*:*:*:*:*:*

History

18 May 2026, 17:17

Type Values Removed Values Added
First Time Fortinet fortideceptor
Fortinet
CPE cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortideceptor:5.2.0:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-138 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-138 - Vendor Advisory

12 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 18:16

Updated : 2026-05-18 17:17


NVD link : CVE-2026-25690

Mitre link : CVE-2026-25690

CVE.ORG link : CVE-2026-25690


JSON object : View

Products Affected

fortinet

  • fortideceptor
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')