CVE-2026-25690
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25690?
The severity of CVE-2026-25690 is classified as high due to potential unauthorized command execution.
How do I fix CVE-2026-25690?
To fix CVE-2026-25690, update FortiDeceptor to the latest version available that addresses this vulnerability.
What versions of FortiDeceptor are affected by CVE-2026-25690?
CVE-2026-25690 affects FortiDeceptor versions 6.0.0 to 6.0.2, 5.3.0 to 5.3.3, 5.2.0 to 5.2.1, and all versions of 5.1 and 5.0.
What type of vulnerability is CVE-2026-25690?
CVE-2026-25690 is an improper neutralization of argument delimiters, also known as argument injection.
Can CVE-2026-25690 lead to data breaches?
Yes, exploitation of CVE-2026-25690 may lead to unauthorized access and potential data breaches.