API Calls being detected as SQL Injection extended Attack in FortiGate
Confirmed 7/20/2026
Problem
There was a case where WAF has blocked the Access to a publicly accessible Server.
Symptoms
after entering the Login credentials and the OTP code the page stays white and no login is successful. After looking at the security logs of FortiGate it has been noticed that the API call has been falsely identifed as an SQL injection extended attack and hence blocked.
Environment
FortiGate
FortiOS version
All versions
Root Cause
API Calls being detected as SQL Injection
Solution
To solve the issue and allow this legitime access the API must be overriden in the WAF profile as a trusted Entry. Cli command:
config waf profile edit "profile name" config signature config url-access edit 1 set address "object name" set log enable config access-pattern edit 1 set pattern "API link" for example : /webapi/entry.cgi/ end end end end
Tags
No tags yet.
Community rating
— / 5 (0)