← All Advisories

Fortinet FortiManager SQL Injection Scores 7.2

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2025-61848

Key Details

CVECVE-2025-61848
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsFortinet FortiManager, Fortinet FortiManager Cloud, Fortinet FortiAnalyzer, and Fortinet FortiAnalyzer Cloud
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
Exploitation prediction (EPSS)0.51% probability of exploitation in the next 30 days (41% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
FortinetFortiManager
FortinetFortiManager Cloud
FortinetFortiAnalyzer
FortinetFortiAnalyzer Cloud
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API

What to Do

Monitor Fortinet's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-61848
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-61848
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-26-111