CVE-2026-21643
Description
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Summary dbcve.org
A SQL injection vulnerability in FortiClientEMS 7.4.4 allows unauthenticated attackers to inject malicious SQL commands via specially crafted HTTP requests. The critical severity (9.8) stems from the ability to execute unauthorized code or commands, indicating the application likely has database-level privileges that permit stacked queries or OS-level command execution through SQL functionality.
Mitigation
Apply the vendor patch or upgrade FortiClientEMS to a version beyond 7.4.4 as specified in Fortinet's security advisory. As a temporary measure, restrict network access to the EMS management interface to trusted IP addresses only.