SQL Injection Vulnerability in Fortinet FortiNDR Products
CVE-2026-25088

5.1MEDIUM

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-25088?

An SQL injection vulnerability exists in Fortinet's FortiNDR products that could enable an authenticated attacker to execute unauthorized code or commands through specially crafted HTTP requests. This flaw affects multiple versions of FortiNDR, potentially exposing systems to various risks and exploits. It is crucial for users to upgrade their products to the latest patched versions to mitigate these vulnerabilities.

Affected Version(s)

FortiNDR 7.6.0 <= 7.6.2

FortiNDR 7.4.0 <= 7.4.9

FortiNDR 7.2.0 <= 7.2.5

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.