
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68648 is a use of externally-controlled format string vulnerability (CWE-134) in the fazsvcd daemon of Fortinet FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud. It affects FortiAnalyzer and FortiManager versions 7.0 (all), 7.2 (all), 7.4.0–7.4.7, and 7.6.0–7.6.4, along with their respective Cloud variants. The vulnerability was internally discovered by David Maciejak of Fortinet's Product Security team and publicly disclosed on March 10, 2026. It carries a CVSS v3.1 base score of 7.2 (High) per NVD, or 6.5 (Medium) per Fortinet's own advisory scoring (FortiGuard Advisory).
The vulnerability is classified as CWE-134 (Use of Externally-Controlled Format String) and resides in the fazsvcd daemon component, accessible via the API. An attacker who has already obtained a remote privileged account with an admin profile can send specially crafted requests that inject format string specifiers, causing the daemon to interpret attacker-controlled data as format strings. This can lead to arbitrary code or command execution on the affected system. Exploitation requires network access and authenticated high-privilege credentials, limiting the attack surface but not eliminating risk in environments with compromised admin accounts (FortiGuard Advisory).
Successful exploitation allows a remote privileged attacker to escalate privileges and execute arbitrary code or commands on affected FortiAnalyzer and FortiManager instances. Given that these products serve as centralized network management and logging platforms, compromise could expose sensitive network telemetry, device configurations, and credentials across the managed infrastructure. The high confidentiality, integrity, and availability impact scores reflect the potential for full system compromise and lateral movement to managed network devices (FortiGuard Advisory).
fazsvcd daemon that includes format string specifiers (e.g., %n, %x, %s) in a parameter that is passed unsanitized to a format string function.fazsvcd daemon processes the format string, allowing the attacker to read memory, overwrite memory locations, or execute arbitrary commands with elevated privileges on the host system (FortiGuard Advisory).Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following fixed releases:
No specific configuration-based workaround is provided by Fortinet. As a general hardening measure, restrict administrative access to FortiAnalyzer and FortiManager to trusted IP ranges and enforce multi-factor authentication on admin accounts (FortiGuard Advisory).
The vulnerability was covered by cybersecurity news outlets as part of Fortinet's March 2026 security update batch. Coverage noted the format string flaw alongside other vulnerabilities patched in the same release cycle (Cybersecurity News). No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."