SQL Injection via JSON RPC API
CVSSv3 Score: 6.8 An improper neutralization of special elements used in an SQL command ('SQL injection') [CWE-89] in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-04-14 00:00:00
CSIRTS triage
- What
- Authenticated privileged attackers may execute unauthorized SQL commands via crafted requests.
- Who is affected
- Authenticated privileged users of the specified Fortinet products.
- Urgency
- Remediation is urgent due to the potential for database compromise.
- Action
- Apply security updates to mitigate SQL injection risks.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, FortiManager Cloud
Get an email when a new FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, FortiManager Cloud advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-111
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-618480.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-61848 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for SQL Injection via
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-77824: The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL In…nvd · 2026-08-25
- highCVE-2026-19949: The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via…nvd · 2026-08-25
- mediumCVE-2026-15023: The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable…nvd · 2026-08-25
- criticalCVE-2026-51366: SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attac…nvd · 2026-08-19
- highGHSA-w27m-rmmf-g5w4: Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Da…ghsa · 2026-08-18
- criticalCVE-2026-51346: SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remo…nvd · 2026-08-17
More from Fortinet FortiGuard PSIRT
- unknownServer-Side Request Forgery (SSRF)2026-08-12
- unknownContent-Encoding WAF Evasion2026-08-12
- unknownHeap overflow in kernel driver due to missing size validation2026-08-12
- unknownBroken access control in the RADIUS type admin group2026-08-12
- unknownUI DoS attack2026-08-12