Improper Neutralization of Argument Delimiters in a Command in FortiDeceptor - CVE-2026-25690
Published: May 12, 2026
FortiDeceptor
Detailed vulnerability description
The vulnerability allows a remote user to read log files.
The vulnerability exists due to improper neutralization of argument delimiters in a command in the FortiDeceptor web UI when handling crafted HTTP requests. A remote user can send a specially crafted request to read log files.
The issue requires at least read-only administrative permission.