FG-IR-26-095: SQL injection in jsonrpc api
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiAnalyzer and FortiAnalyzer-BigData API may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-095?
The FG-IR-26-095 vulnerability is classified as a critical SQL injection vulnerability.
How do I fix FG-IR-26-095?
To mitigate FG-IR-26-095, upgrade FortiAnalyzer and FortiAnalyzer-BigData to the latest patched version.
Who is affected by FG-IR-26-095?
FG-IR-26-095 affects specific versions of FortiAnalyzer and FortiAnalyzer-BigData, particularly versions 7.6.0 to 7.6.4 and 7.4.0 to 7.4.7.
Can FG-IR-26-095 lead to data breaches?
Yes, FG-IR-26-095 may allow authenticated attackers to execute unauthorized code, potentially leading to data breaches.
What should I do if I'm using a vulnerable version related to FG-IR-26-095?
If using a vulnerable version related to FG-IR-26-095, immediately upgrade to a secure version recommended by Fortinet.