CVE-2026-25088
FortiNDR vulnerability analysis and mitigation

Overview

CVE-2026-25088 is a SQL injection vulnerability (CWE-89) in Fortinet FortiNDR that may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specially crafted HTTP requests. It affects FortiNDR versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.9, and all versions of 7.2, 7.1, and 7.0. The vulnerability was internally discovered and reported by Dipanjan Das, with initial publication on May 12, 2026. The official Fortinet PSIRT advisory assigns a CVSSv3 score of 5.1 (Medium), while NVD rates it 8.8 (High) (FortiGuard PSIRT).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and resides in the FortiNDR GUI component. An authenticated attacker can send specifically crafted HTTP requests that embed malicious SQL syntax, which the application fails to properly sanitize before passing to the database engine, enabling arbitrary SQL command execution. Exploitation requires valid credentials (low-privilege) and network access to the FortiNDR management interface, but no user interaction is needed. No public proof-of-concept code has been identified at this time (FortiGuard PSIRT).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the FortiNDR database, potentially exposing sensitive network detection and response data, configuration details, and stored credentials. Depending on database permissions, an attacker could also modify or delete data, undermining the integrity of the NDR platform. The confidentiality, integrity, and availability impacts are all rated High under the NVD CVSS scoring (FortiGuard PSIRT).

Exploitability

Fortinet has confirmed that this vulnerability is not known to be exploited in the wild as of the advisory publication date. The attack requires authenticated access with low privileges, reducing the risk compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term. No exploit kits, weaponized code, or threat actor attribution have been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (FortiGuard PSIRT).

Exploitation steps

  1. Reconnaissance: Identify FortiNDR instances running affected versions (7.0.x, 7.1.x, 7.2.x, 7.4.0–7.4.9, or 7.6.0–7.6.2) by scanning for exposed management interfaces or using OSINT techniques.
  2. Authentication: Obtain valid FortiNDR credentials (low-privilege account sufficient) through phishing, credential stuffing, or other means.
  3. Craft malicious HTTP request: Construct an HTTP request targeting a vulnerable GUI endpoint that accepts user-controlled input passed to SQL queries, embedding SQL injection payloads (e.g., ' OR 1=1--, UNION SELECT, or time-based blind injection techniques).
  4. Execute SQL commands: Submit the crafted request to the FortiNDR management interface; the unsanitized input is interpreted by the database engine, allowing extraction of data, modification of records, or further command execution depending on database privileges.
  5. Exfiltrate or manipulate data: Use the SQL injection foothold to enumerate database tables, extract sensitive configuration or credential data, or alter detection rules stored in the database (FortiGuard PSIRT).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to the FortiNDR management GUI containing SQL metacharacters (e.g., single quotes, UNION, SELECT, --, OR 1=1) in parameter values; unexpected outbound database connections from the FortiNDR host.
  • Logs: FortiNDR application or web server logs showing HTTP requests with anomalous query parameters or unusually long parameter strings; database error messages logged in application logs indicating SQL syntax errors from injected payloads.
  • Process/Behavior: Unexpected database queries executing against sensitive tables (e.g., user credentials, configuration tables) outside of normal operational patterns; elevated database activity or large data reads from the FortiNDR database service.

Mitigation and workarounds

Fortinet has released patched versions to address this vulnerability. Administrators should upgrade to the following fixed releases: FortiNDR 7.6.3 or above (for 7.6.x users), FortiNDR 7.4.10 or above (for 7.4.x users). Users running FortiNDR 7.2, 7.1, or 7.0 (all versions affected) should migrate to a fixed release as no in-branch patch is available. As an interim measure, restrict access to the FortiNDR management interface to trusted IP addresses and enforce the principle of least privilege for all accounts (FortiGuard PSIRT).

Community reactions

Coverage of CVE-2026-25088 has been limited to routine security news aggregators and patch Tuesday roundups. TheCyberThrone covered it as part of Fortinet's May 2026 patch cycle, and the Egyptian Financial CERT (EGFinCIRT) published a security update notice referencing the advisory. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (TheCyberThrone, EGFinCIRT).

Additional resources


SourceThis report was generated using AI

Related FortiNDR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-32756CRITICAL9.8
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
YesYesMay 13, 2025
CVE-2026-25088HIGH8.8
  • FortiNDR logoFortiNDR
  • cpe:2.3:a:fortinet:fortindr
NoYesMay 12, 2026
CVE-2024-40588MEDIUM4.4
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoYesAug 12, 2025
CVE-2024-23104MEDIUM4.3
  • FortiNDR logoFortiNDR
  • cpe:2.3:a:fortinet:fortindr
NoYesApr 14, 2026
CVE-2024-47569MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesOct 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management