CVE-2023-26210: Fortinet FortiADC

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests.

Affected products

  • Fortinet FortiADC: from 5.2.0, up to and including 5.2.8; from 5.3.0, up to and including 5.3.7; from 5.4.0, up to and including 5.4.5; from 6.0.0, up to and including 6.0.4; from 6.1.0, up to and including 6.1.6; from 6.2.0, up to and including 6.2.6; …
  • Fortinet FortiADC Manager: version 5.2.0 only; version 5.2.1 only; version 5.3.0 only; version 5.4.0 only; version 6.0.0 only; version 6.1.0 only; …

Published 2023-06-13. Last modified 2026-06-17.