Multiple OS command injection in API and CLI

Summary

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Fortinet has observed this to be exploited in the wild.

FortiAppSec Cloud is NOT impacted by this vulnerability.

Version Affected Solution
FortiWeb 8.0 8.0.0 through 8.0.1 Upgrade to 8.0.2 or above
FortiWeb 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above
FortiWeb 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above
FortiWeb 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above
FortiWeb 7.0 7.0.0 through 7.0.11 Upgrade to 7.0.12 or above
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Discovered by Fortinet Threat intelligence with additional thanks to Jason McFadyen from Trend Research (Trend Micro).

Timeline

2025-11-18: Initial publication