← Back

CVE-2025-68649

nvd nist
Published: Apr 14, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.

Affected (8)

4 products
Fortimanager Cloud
Fortimanager
Fortianalyzer Cloud
Fortianalyzer
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.8
From 7.6.0 to 7.6.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.8
From 7.6.0 to 7.6.5
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.8
From 7.6.0 to 7.6.5
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.8
From 7.6.0 to 7.6.5

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.