Medium SEVERITY — Vulnerability

User controlled SQL commands

CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests. Revised on 2026-05-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
5.1/10
Advisory
FG-IR-26-134
Published
12 May 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests. Revised on 2026-05-12 00:00:00

Source

  • [Open vendor advisory](https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-134)

This record was ingested automatically; verify the content before publishing.

FortiGate / FortiOS — Related Advisories

VIEW ALL →