Executive brief
FortiDeceptor is a security appliance used to detect and deceive attackers within a network. A vulnerability in its management interface allows an authorized user with basic read-only access to view sensitive system log files they should not be able to see. This could lead to the exposure of internal system information or operational data, potentially aiding further unauthorized activities.
Technical details
An argument injection vulnerability (CWE-88) exists in the FortiDeceptor Web UI due to improper neutralization of argument delimiters in a command. An authenticated attacker with at least read-only administrative permissions can exploit this by sending specially crafted HTTP requests to the management interface. Successful exploitation allows the attacker to read arbitrary log files on the system. The vulnerability affects multiple versions across the 5.x and 6.0.x branches; users are advised to migrate to a fixed release such as 6.1 or higher where the issue is not present.
Affected products
- Fortinet FortiDeceptor 6.0.0 through 6.0.2, 5.3.0 through 5.3.3, 5.2.0 through 5.2.1, 5.1 all versions, 5.0 all versions
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory