FG-IR-26-133: OS command injection in CLI
Published May 12, 2026
·Updated
An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.
Affected Software
8 affected componentsFixes available
Fortinet FortiAP>=7.6.0<=7.6.2
Fortinet FortiAP>=7.4.0<=7.4.5
Fortinet FortiAP>=7.2
Fortinet FortiAP>=7.0
Fortinet FortiAP>=6.4
Fortinet FortiAP-W2>=7.4.0<=7.4.4
Fortinet FortiAP-W2>=7.2.0<=7.2.5
Fortinet FortiAP-W2>=7.0
Event History
May 12, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-133?
The severity of FG-IR-26-133 is considered critical due to the potential for unauthorized command execution.
2
How do I fix FG-IR-26-133?
To fix FG-IR-26-133, upgrade FortiAP to version 7.6.3 or above, or FortiAP-W2 to version 7.4.5 or above.
3
What systems are affected by FG-IR-26-133?
FG-IR-26-133 affects FortiAP versions 7.6.0 to 7.6.2 and 7.4.0 to 7.4.5, as well as specific older versions of FortiAP and FortiAP-W2.
4
What type of vulnerability is FG-IR-26-133?
FG-IR-26-133 is classified as an OS command injection vulnerability, allowing execution of unauthorized commands.
5
Who can exploit FG-IR-26-133?
An authenticated attacker can exploit FG-IR-26-133 by crafting specific CLI commands.