CVE-2026-39815: SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39815?
CVE-2026-39815 is classified as a critical severity vulnerability due to the potential for unauthorized execution of code.
How do I fix CVE-2026-39815?
To mitigate CVE-2026-39815, upgrade Fortinet FortiDDoS-F to version 7.2.3 or later.
What systems are affected by CVE-2026-39815?
CVE-2026-39815 affects Fortinet FortiDDoS-F versions 7.2.1 through 7.2.2.
What type of vulnerability is CVE-2026-39815?
CVE-2026-39815 is an SQL injection vulnerability that allows attackers to execute unauthorized commands.
How can an attacker exploit CVE-2026-39815?
An attacker can exploit CVE-2026-39815 by sending specially crafted SQL commands to the vulnerable Fortinet FortiDDoS-F application.