An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-134 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 May 2026, 17:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-134 - Vendor Advisory | |
| First Time |
Fortinet fortindr
Fortinet |
|
| CPE | cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:* |
12 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 18:16
Updated : 2026-06-17 10:24
NVD link : CVE-2026-25088
Mitre link : CVE-2026-25088
CVE.ORG link : CVE-2026-25088
JSON object : View
Products Affected
fortinet
- fortindr
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
