Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Fortinet FortiManager — An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 thr…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0051 41.4 —
AFFECTED
Product Versions Fixed
FortiManager 7.6.0 – —
FortiAnalyzer 7.6.0 – —
FortiAnalyzer-BigData 7.6.0 – —
FortiManager Cloud 7.6.2 – —
FortiAnalyzer Cloud 7.6.2 – —
TIMELINE
Oct 1 Reserved by fortinet
Apr 14 Published (CNA: fortinet)
Aug 12 RESCORED — CVE-2025-61848 (Fortinet FortiManager). CVSS 6.5 → 7.2 (NVD).
Description
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 1, 2025 | Reserved | Reserved by fortinet |
| April 14, 2026 | Published | Published (CNA: fortinet) |
| August 12, 2026 | RESCORED | RESCORED — CVE-2025-61848 (Fortinet FortiManager). CVSS 6.5 → 7.2 (NVD). |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Fortinet | FortiManager | — | 7.6.0 | — |
| Fortinet | FortiAnalyzer | — | 7.6.0 | — |
| Fortinet | FortiAnalyzer-BigData | — | 7.6.0 | — |
| Fortinet | FortiManager Cloud | — | 7.6.2 | — |
| Fortinet | FortiAnalyzer Cloud | — | 7.6.2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-61848 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.