CVE-2025-68649
Fortinet FortiManager vulnerability analysis and mitigation

Overview

CVE-2025-68649 is a path traversal vulnerability (CWE-22) in Fortinet FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud that allows a privileged attacker to delete arbitrary files from the underlying filesystem via crafted CLI requests. It was internally discovered by David Maciejak of the Fortinet Product Security team and publicly disclosed on April 14, 2026. Affected versions span FortiAnalyzer/FortiManager 7.0.x through 7.6.4 (all 7.0 and 7.2 versions, 7.4.0–7.4.7, and 7.6.0–7.6.4), with corresponding Cloud variants equally affected; version 6.4 is not affected. The vulnerability carries a CVSSv3.1 base score of 5.4 (Medium) per Fortinet's advisory, though NVD rates it 6.5 (Medium) (Fortinet Advisory).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal), classified under CAPEC-126. An authenticated, privileged attacker can craft CLI requests containing path traversal sequences (e.g., ../) that bypass directory restrictions enforced by the CLI input handling logic, enabling file deletion operations outside the intended filesystem scope. Exploitation requires network access and high-level privileges (authenticated administrator or equivalent), with no user interaction needed. The vulnerability was discovered internally and no public proof-of-concept or technical write-up has been released (Fortinet Advisory).

Impact

Successful exploitation allows a privileged attacker to delete arbitrary files from the underlying filesystem of affected FortiAnalyzer or FortiManager appliances, impacting integrity and availability with no direct confidentiality impact. Deletion of critical system or configuration files could cause service disruption, system instability, or loss of log/management data essential to network security operations. Because FortiManager and FortiAnalyzer are central management and logging platforms, their disruption could impair visibility and control across managed Fortinet infrastructure (Fortinet Advisory).

Mitigation and workarounds

Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following fixed releases:

  • FortiAnalyzer / FortiManager 7.6.x: Upgrade to 7.6.5 or above
  • FortiAnalyzer / FortiManager 7.4.x: Upgrade to 7.4.8 or above
  • FortiAnalyzer / FortiManager 7.2.x and 7.0.x: Migrate to a fixed release (no in-branch fix available)
  • Cloud variants: Apply corresponding patched versions per the above branches

As compensating controls, restrict CLI access to trusted administrators only, implement least-privilege access policies, and monitor CLI activity logs for suspicious file-related commands. No specific workaround short of upgrading has been published by Fortinet (Fortinet Advisory).

Community reactions

Fortinet disclosed the vulnerability as part of a broader April 2026 patch release covering 11 vulnerabilities across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager. Security news outlets including CyberSecurityNews, CyberPress, and Cryptika covered the patch batch, though CVE-2025-68649 received limited individual attention given its medium severity and authentication requirement. The CIS issued an advisory noting multiple Fortinet vulnerabilities in the same release cycle (CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Fortinet FortiManager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61848HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesApr 14, 2026
CVE-2026-22572HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026
CVE-2025-68649MEDIUM6.5
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortimanager
NoYesApr 14, 2026
CVE-2025-67604MEDIUM5.3
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMay 12, 2026
CVE-2026-22629LOW3.7
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management