CVE-2023-27995: Fortinet Fortisoar

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.

Affected products

  • Fortinet Fortisoar: from 7.3.0, before 7.3.2 (fixed in 7.3.2)

Published 2023-04-11. Last modified 2026-06-17.