Junglewise Threat Intelligence

CVE-2025-53681: Fortinet FortiMail SQL injection in administrative portal

CVE-2025-53681 · Severity: high · CVSS 7.2 · Published 2026-05-12

Vendors: Fortinet.

Executive brief

FortiMail is a secure email gateway used to protect organizations from email-based threats like spam and malware. A security flaw in its management interface could allow an administrator with existing access to execute unauthorized commands or code on the system. This could lead to a full compromise of the email security appliance and the sensitive data it processes.

Technical details

An SQL injection vulnerability (CWE-89) exists in the administrative GUI component of Fortinet FortiMail. The flaw stems from improper neutralization of special elements within SQL commands. An attacker with high-level administrative privileges can exploit this by sending specially crafted HTTP or HTTPS requests to the management portal. Successful exploitation allows for the execution of unauthorized code or commands on the underlying system. The vulnerability affects versions 7.6.0-7.6.3, 7.4.0-7.4.5, and 7.2.0-7.2.8, and is resolved in versions 7.6.4, 7.4.6, and 7.2.9 respectively.

Affected products

  • Fortinet FortiMail 7.6.0 through 7.6.3, 7.4.0 through 7.4.5, 7.2.0 through 7.2.8

Timeline

  • 2026-05-12: disclosed: Initial publication by Fortinet
  • 2026-05-12: advisory: NVD record published

References