Medium SEVERITY — Vulnerability

SQL command injection in administrative portal

CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests. Revised on 2026-05-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
6.3/10
Advisory
FG-IR-26-132
Published
12 May 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests. Revised on 2026-05-12 00:00:00

Source

  • [Open vendor advisory](https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-132)

This record was automatically ingested; verify the content before publishing.

FortiGate / FortiOS — Related Advisories

VIEW ALL →