CRITICAL

CVE-2026-21643

Fortinet Forticlientems 2026-02-06 CVSS v3.1
CVSS
9.8
KEV

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Summary dbcve.org

A SQL injection vulnerability in FortiClientEMS 7.4.4 allows unauthenticated attackers to inject malicious SQL commands via specially crafted HTTP requests. The critical severity (9.8) stems from the ability to execute unauthorized code or commands, indicating the application likely has database-level privileges that permit stacked queries or OS-level command execution through SQL functionality.

Mitigation

Apply the vendor patch or upgrade FortiClientEMS to a version beyond 7.4.4 as specified in Fortinet's security advisory. As a temporary measure, restrict network access to the EMS management interface to trusted IP addresses only.

Proof of Concept

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

94.09%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE