CVE-2025-61848

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.

Severity
Medium 6.8
CVSS 3.1
Exploited
Not listed
EPSS
0.005
40.7th percentile
Discovered by
Not disclosed
Published
Apr 14, 2026
Assigned by fortinet

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.8, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API

Weakness: CWE-89

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported affected versions (4)
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer
  • Fortinet · FortiManager Cloud
  • Fortinet · FortiAnalyzer Cloud

Vendor remediation

Upgrade to upcoming FortiManager version 8.0.0 or above Upgrade to FortiManager version 7.6.5 or above Upgrade to FortiManager version 7.4.9 or above Upgrade to FortiAnalyzer version 7.6.5 or above Upgrade to FortiAnalyzer version 7.4.9 or above Upgrade to FortiAnalyzer Cloud version 7.6.4 or above Upgrade to FortiManager Cloud version 7.6.5 or above