Improper Neutralization of Argument Delimiters in a Command in FortiDeceptor - CVE-2026-25690
Published: May 12, 2026
Vulnerability details
The vulnerability allows a remote user to read log files.
The vulnerability exists due to improper neutralization of argument delimiters in a command in the FortiDeceptor web UI when handling crafted HTTP requests. A remote user can send a specially crafted request to read log files.
The issue requires at least read-only administrative permission.