Junglewise Threat Intelligence

CVE-2026-25088: Fortinet FortiNDR SQL injection in GUI

CVE-2026-25088 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Vendors: Fortinet.

Executive brief

FortiNDR is a network detection and response solution used to identify and analyze cyber threats within a corporate network. A security vulnerability in its management interface could allow a logged-in user to run unauthorized database commands. This could lead to the unauthorized viewing or modification of internal security data and system configurations.

Technical details

An improper neutralization of special elements used in an SQL command (CWE-89) exists in the GUI component of Fortinet FortiNDR. The vulnerability allows an authenticated attacker with network access to the management interface to execute arbitrary SQL commands on specific databases and tables by sending specially crafted HTTP requests. The flaw affects multiple major versions including 7.0, 7.1, 7.2, 7.4, and 7.6. Users are advised to upgrade to versions 7.6.3, 7.4.10, or other subsequent fixed releases as specified by the vendor.

Affected products

  • Fortinet FortiNDR 7.6.0 through 7.6.2, 7.4.0 through 7.4.9, 7.2 all versions, 7.1 all versions, 7.0 all versions

Timeline

  • 2026-05-12: disclosed: Initial publication of the advisory by Fortinet.
  • 2026-05-12: advisory: NVD published the CVE record.

References