← Vulnerability feed

Vulnerability record · CVE-2021-22123 · published 1 June 2021

CVE-2021-22123: FortiWeb management interface OS command injection via SAML config

Fortinet · Fortiweb

FortiWeb's management interface contains an OS command injection flaw (CWE-78) reachable through the SAML server configuration page. It affects versions 6.3.7 and below, 6.2.3 and below, and the 6.1.x, 6.0.x and 5.9.x branches. Because the injected commands run on the appliance itself, a successful attack undermines the device's role as a security control.

8.8 CVSS 3.1 High EPSS 77% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote authenticated command injection with high confidentiality, integrity and availability impact, plus a very high EPSS score, warrants prompt patching despite no KEV listing.

What it is

FortiWeb's management interface contains an OS command injection flaw (CWE-78) reachable through the SAML server configuration page. It affects versions 6.3.7 and below, 6.2.3 and below, and the 6.1.x, 6.0.x and 5.9.x branches. Because the injected commands run on the appliance itself, a successful attack undermines the device's role as a security control.

Impact

An attacker with valid management credentials can execute arbitrary operating system commands on the FortiWeb appliance, gaining full control of the device and any data or credentials it handles.

Attack surface

Reached over the network through the FortiWeb management interface, specifically the SAML server configuration page. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a remote attacker who is authenticated with low privileges and requires no user interaction.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is very high at 0.7727 (99.5th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Upgrade FortiWeb to a fixed release per FortiGuard advisory FG-IR-20-120; versions 6.3.7, 6.2.3, 6.1.x, 6.0.x and 5.9.x are affected.
  • Restrict management interface access to trusted administrative networks and disable it on internet-facing interfaces.
  • Enforce least privilege and strong authentication for management accounts, and remove unused accounts.
  • Monitor and alert on unexpected child processes or shell activity spawned by the web management service.

Detection

  • Audit SAML server configuration changes in FortiWeb logs and alert on unexpected modifications.
  • Monitor appliance process trees for shell or command interpreters spawned by the management web service.
  • Review management interface access logs for anomalous source IPs or unusual request patterns to SAML configuration endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-64446FortiWeb relative path traversal allows admin command executionFortiWeb contains a relative path traversal flaw (CWE-23) reachable through crafted HTTP or HTTPS requests. Successful exploitation lets an attacker …KEVEPSS 92%analysed9.8CVE-2025-25257FortiWeb unauthenticated SQL injection via HTTP requestsFortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands…KEVEPSS 100%analysed7.2CVE-2025-58034FortiWeb OS command injection via crafted HTTP or CLI inputFortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the …KEVEPSS 56%analysed9.8CVE-2026-26035Fortinet fortiweb improper authentication vulnerabilityAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…EPSS 0.75%9.8CVE-2025-59719Fortinet fortiweb improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…EPSS 29%9.8CVE-2023-25610Fortinet fortiweb vulnerabilityA buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…EPSS 18%9.8CVE-2024-55594Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2021-22123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.