CVE-2026-25690 PUBLISHED

Assigner: fortinet
Reserved: 05.02.2026 Published: 12.05.2026 Updated: 12.05.2026

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C
CVSS Score: 4

Product Status

Vendor Fortinet
Product FortiDeceptor
Versions Default: unaffected
  • affected from 6.0.0 to 6.0.2 (incl.)
  • affected from 5.3.0 to 5.3.3 (incl.)
  • affected from 5.2.0 to 5.2.1 (incl.)
  • Version 5.1.0 is affected
  • Version 5.0.0 is affected

Solutions

Upgrade to upcoming FortiDeceptor version 6.3.0 or above Upgrade to FortiDeceptor version 6.1.0 or above

References

Problem Types

  • Information disclosure CWE