
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49784 is an SQL injection vulnerability (CWE-89) in Fortinet FortiAnalyzer and FortiAnalyzer-BigData products, specifically within the JSON-RPC API. It allows an authenticated attacker with high privileges to execute unauthorized code or commands via specially crafted requests. Affected versions include FortiAnalyzer 6.4 all versions through 7.6.4, and FortiAnalyzer-BigData 6.2 all versions through 7.6.0. The vulnerability was published on March 10, 2026. It carries a CVSS v3.1 base score of 7.2 (High) per NVD, and 5.6 (Medium) per Fortinet's own advisory (FortiGuard Advisory).
The root cause is improper neutralization of special elements in SQL commands (CWE-89) within the FortiAnalyzer and FortiAnalyzer-BigData JSON-RPC API. An authenticated attacker can craft malicious API requests that inject SQL syntax, potentially enabling arbitrary code or command execution on the backend. Critically, the vulnerability is only exploitable when the JSON API feature is enabled on an administrator profile — this feature is disabled by default. The attack vector is network-based, requires no user interaction, but does require high-privilege authentication (FortiGuard Advisory).
Successful exploitation could allow an authenticated high-privilege attacker to execute arbitrary code or commands on the affected FortiAnalyzer system, resulting in high confidentiality, integrity, and availability impacts. Attackers could access sensitive security analytics data stored in FortiAnalyzer, modify system configurations, or disrupt normal platform operations. Given FortiAnalyzer's role as a centralized log management and analytics platform, compromise could expose network-wide security telemetry and facilitate further lateral movement (FortiGuard Advisory).
', --, UNION, SELECT) in API parameters.Fortinet has released patched versions: FortiAnalyzer 7.6.5 or above, FortiAnalyzer 7.4.8 or above, and FortiAnalyzer-BigData 7.6.1 or above, and FortiAnalyzer-BigData 7.4.5 or above. Users on FortiAnalyzer 7.2, 7.0, 6.4, and FortiAnalyzer-BigData 7.2, 7.0, 6.4, and 6.2 should migrate to a fixed release. As an immediate workaround, disable the JSON API on administrator profiles if it is not required, using the CLI command: config system admin profile / edit <profile> / set rpc-permit none / end. Additionally, restrict administrative access to FortiAnalyzer systems to only authorized personnel and implement network segmentation to limit exposure (FortiGuard Advisory).
Coverage of CVE-2025-49784 was primarily limited to security news aggregators and vulnerability tracking platforms at the time of disclosure. CyberSecurityNews.com covered it as part of Fortinet's March 2026 security update batch. No significant independent researcher commentary or notable social media discussion has been identified beyond routine vulnerability tracking (FortiGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."