Back

HIGH

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests

Published May 12, 2026

Description

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

Affected products

Remediation

Vendor solution

Upgrade to FortiMail version 7.6.4 or above Upgrade to FortiMail version 7.4.6 or above Upgrade to FortiMail version 7.2.9 or above Fortinet remediated this issue in FortiMail Cloud version 25.2 and hence customers do not need to perform any action.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published May 12, 2026
Updated Jul 8, 2026
Reserved Jul 8, 2025
CISA Vulnrichment
Updated May 12, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a