
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68649 is a path traversal vulnerability (CWE-22) in Fortinet FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud that allows a privileged attacker to delete arbitrary files from the underlying filesystem via crafted CLI requests. It was internally discovered by David Maciejak of the Fortinet Product Security team and publicly disclosed on April 14, 2026. Affected versions span FortiAnalyzer/FortiManager 7.0.x through 7.6.4 (all 7.0 and 7.2 versions, 7.4.0–7.4.7, and 7.6.0–7.6.4), with corresponding Cloud variants equally affected; version 6.4 is not affected. The vulnerability carries a CVSSv3.1 base score of 5.4 (Medium) per Fortinet's advisory, though NVD rates it 6.5 (Medium) (Fortinet Advisory).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal), classified under CAPEC-126. An authenticated, privileged attacker can craft CLI requests containing path traversal sequences (e.g., ../) that bypass directory restrictions enforced by the CLI input handling logic, enabling file deletion operations outside the intended filesystem scope. Exploitation requires network access and high-level privileges (authenticated administrator or equivalent), with no user interaction needed. The vulnerability was discovered internally and no public proof-of-concept or technical write-up has been released (Fortinet Advisory).
Successful exploitation allows a privileged attacker to delete arbitrary files from the underlying filesystem of affected FortiAnalyzer or FortiManager appliances, impacting integrity and availability with no direct confidentiality impact. Deletion of critical system or configuration files could cause service disruption, system instability, or loss of log/management data essential to network security operations. Because FortiManager and FortiAnalyzer are central management and logging platforms, their disruption could impair visibility and control across managed Fortinet infrastructure (Fortinet Advisory).
Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following fixed releases:
As compensating controls, restrict CLI access to trusted administrators only, implement least-privilege access policies, and monitor CLI activity logs for suspicious file-related commands. No specific workaround short of upgrading has been published by Fortinet (Fortinet Advisory).
Fortinet disclosed the vulnerability as part of a broader April 2026 patch release covering 11 vulnerabilities across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager. Security news outlets including CyberSecurityNews, CyberPress, and Cryptika covered the patch batch, though CVE-2025-68649 received limited individual attention given its medium severity and authentication requirement. The CIS issued an advisory noting multiple Fortinet vulnerabilities in the same release cycle (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."