Multiple authenticated OS Command Injections via API

Summary

An OS command injection vulnerabtility [CWE-78] in FortiExtender API may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

Version Affected Solution
FortiExtender 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiExtender 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiExtender 7.2 7.2 all versions Migrate to a fixed release
FortiExtender 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by David Maciejak of Fortinet Product Security team.

Timeline

2025-12-09: Initial publication