Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-21643 — CVE-2026-21643 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-21643
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHub0xblackash/cve-2026-21643

CVE-2026-21643

CVE-2026-21643

View Repository
18796 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-21643 "FortiGhost" : Pre-Auth SQLi RCE in FortiClientEMS

bfx25_Blog-Forticlient-CVE-2026-21643-F

Critical CVSS Fortinet Published

Unauthenticated SQL Injection in FortiClientEMS 7.4.4
Potential Remote Code Execution via crafted HTTP requests to the admin GUI


📋 Overview

CVE-2026-21643 is a critical SQL injection vulnerability (CWE-89) affecting Fortinet FortiClient Endpoint Management Server (FortiClientEMS) version 7.4.4 only.

An unauthenticated remote attacker can send specially crafted HTTP requests to the web-based administrative interface (GUI) and execute unauthorized SQL commands. This can lead to full system compromise, including arbitrary code execution on the server.

Key Risk: The vulnerability is pre-authentication, making any internet-exposed or reachable FortiClientEMS instance a high-value target.


🔍 Technical Details

cve-2026-21643
  • CVE ID: CVE-2026-21643
  • Fortinet IR: FG-IR-25-1142
  • Severity: Critical
  • CVSS v3.1 Score: 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  • Vulnerability Type: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
  • Affected Component: Administrative Web Interface (GUI)
  • Attack Vector: Remote, via specially crafted HTTP requests (reportedly involving the Site header in multi-tenant setups and endpoints like /api/v1/init_consts)
  • Authentication Required: None
  • User Interaction: None
  • Known Public Exploitation: No (as of March 2026)
  • Discovered By: Internally by Fortinet (Gwendal Guégniaud, Product Security team)

📊 Affected Versions

ProductVersionStatusFixed In
FortiClientEMS7.4.4AffectedUpgrade to 7.4.5+
FortiClientEMS7.4.xOnly 7.4.47.4.5 or later
FortiClientEMS7.2.xNot affected-
FortiClientEMS8.0.xNot affected-
FortiClientEMS CloudAllNot affected-

✅ Remediation

Urgent Action Recommended:

  1. Upgrade immediately to FortiClientEMS 7.4.5 or any newer release (including the 8.0 branch).
  2. Restrict access to the administrative GUI:
    • Place behind a VPN, firewall, or zero-trust solution.
    • Avoid exposing the EMS web interface directly to the internet.
  3. Monitor logs for suspicious requests to admin endpoints (e.g., involving Site header or error-based SQLi patterns).
  4. Apply FortiGuard IPS signatures if available for additional protection.

Official Fortinet Advisory:
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142


🛡️ Mitigation & Best Practices

  • Patch Priority: High — treat as emergency due to pre-auth nature.
  • If patching cannot be done immediately, block external access to the EMS management interface.
  • Review multi-tenant configurations (more exposed due to the Site header handling).
  • Enable detailed logging and monitor for database error leaks.
  • Regularly scan your environment for exposed FortiClientEMS instances.

Note: The flaw was introduced during a middleware refactoring in 7.4.4 related to multi-tenancy support and was silently patched in 7.4.5.


📚 References & Further Reading

  • NVD - CVE-2026-21643
  • Fortinet PSIRT Advisory FG-IR-25-1142
  • Arctic Wolf Analysis
  • The Hacker News Coverage
  • Qualys ThreatPROTECT
  • SentinelOne Vulnerability Database

📌 Disclaimer

This repository is maintained for defensive security, awareness, and informational purposes only. Always refer to the official Fortinet advisory for the most accurate and up-to-date guidance.

No public exploits are included here.


⭐ Star this repo if it helped you stay secure!
🛠️ Contributions, corrections, or additional IOCs are welcome via Pull Requests.

Last Updated: March 2026

Download Tool