
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25088 is a SQL injection vulnerability (CWE-89) in Fortinet FortiNDR that may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specially crafted HTTP requests. It affects FortiNDR versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.9, and all versions of 7.2, 7.1, and 7.0. The vulnerability was internally discovered and reported by Dipanjan Das, with initial publication on May 12, 2026. The official Fortinet PSIRT advisory assigns a CVSSv3 score of 5.1 (Medium), while NVD rates it 8.8 (High) (FortiGuard PSIRT).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and resides in the FortiNDR GUI component. An authenticated attacker can send specifically crafted HTTP requests that embed malicious SQL syntax, which the application fails to properly sanitize before passing to the database engine, enabling arbitrary SQL command execution. Exploitation requires valid credentials (low-privilege) and network access to the FortiNDR management interface, but no user interaction is needed. No public proof-of-concept code has been identified at this time (FortiGuard PSIRT).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the FortiNDR database, potentially exposing sensitive network detection and response data, configuration details, and stored credentials. Depending on database permissions, an attacker could also modify or delete data, undermining the integrity of the NDR platform. The confidentiality, integrity, and availability impacts are all rated High under the NVD CVSS scoring (FortiGuard PSIRT).
Fortinet has confirmed that this vulnerability is not known to be exploited in the wild as of the advisory publication date. The attack requires authenticated access with low privileges, reducing the risk compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term. No exploit kits, weaponized code, or threat actor attribution have been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (FortiGuard PSIRT).
' OR 1=1--, UNION SELECT, or time-based blind injection techniques).UNION, SELECT, --, OR 1=1) in parameter values; unexpected outbound database connections from the FortiNDR host.Fortinet has released patched versions to address this vulnerability. Administrators should upgrade to the following fixed releases: FortiNDR 7.6.3 or above (for 7.6.x users), FortiNDR 7.4.10 or above (for 7.4.x users). Users running FortiNDR 7.2, 7.1, or 7.0 (all versions affected) should migrate to a fixed release as no in-branch patch is available. As an interim measure, restrict access to the FortiNDR management interface to trusted IP addresses and enforce the principle of least privilege for all accounts (FortiGuard PSIRT).
Coverage of CVE-2026-25088 has been limited to routine security news aggregators and patch Tuesday roundups. TheCyberThrone covered it as part of Fortinet's May 2026 patch cycle, and the Egyptian Financial CERT (EGFinCIRT) published a security update notice referencing the advisory. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (TheCyberThrone, EGFinCIRT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."