CVE-2024-48890: Fortinet Fortisoar Imap Connector
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
Affected products
- Fortinet Fortisoar Imap Connector: before 3.5.8 (fixed in 3.5.8)
Published 2025-01-14. Last modified 2026-06-17.