Status: UPDATED | Advisory ID: CVE-2026-39815
| CVE | CVE-2026-39815 |
| CVSS | CVSS 8.8 (High). |
| Affected products | Fortinet fortiddos-f |
| Classified as | CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) |
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-39815 |
| Vendor advisory | https://fortiguard.fortinet.com/psirt/FG-IR-26-119 |