CVE-2025-68648

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versi

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.006
45.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cloud 7.0.1 through 7.0.14 may allow an attacker to escalate its privileges via specially crafted requests.

Weakness: CWE-134

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer Check your version SIEM & Log Management cna-assigner
Fortinet FortiManager Check your version Network & Security Management cna-assigner
Vendor-reported products (4)
  • Fortinet · FortiManager Cloud
  • Fortinet · FortiAnalyzer Cloud
  • Fortinet · FortiAnalyzer
  • Fortinet · FortiManager

Credit

Internally discovered and reported by David Maciejak of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiAnalyzer Cloud version 7.6.5 or above Upgrade to FortiAnalyzer Cloud version 7.4.8 or above Upgrade to FortiAnalyzer version 7.6.5 or above Upgrade to FortiAnalyzer version 7.4.8 or above Upgrade to FortiManager Cloud version 7.6.5 or above Upgrade to FortiManager Cloud version 7.4.8 or above Upgrade to FortiManager version 7.6.5 or above Upgrade to FortiManager version 7.4.8 or above

Something wrong here?