> Remote unauthenticated command injection
[DATE: 12/08/2025 07:00]
[LANGUAGE: EN]
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.Practical exploit code for this vulnerability was found in the wild. Revised on 2025-08-12 00:00:00