
CVE-2026-21643

Unauthenticated SQL Injection in FortiClientEMS 7.4.4
Potential Remote Code Execution via crafted HTTP requests to the admin GUI
CVE-2026-21643 is a critical SQL injection vulnerability (CWE-89) affecting Fortinet FortiClient Endpoint Management Server (FortiClientEMS) version 7.4.4 only.
An unauthenticated remote attacker can send specially crafted HTTP requests to the web-based administrative interface (GUI) and execute unauthorized SQL commands. This can lead to full system compromise, including arbitrary code execution on the server.
Key Risk: The vulnerability is pre-authentication, making any internet-exposed or reachable FortiClientEMS instance a high-value target.
SQL Injection)Site header in multi-tenant setups and endpoints like /api/v1/init_consts)| Product | Version | Status | Fixed In |
|---|---|---|---|
| FortiClientEMS | 7.4.4 | Affected | Upgrade to 7.4.5+ |
| FortiClientEMS | 7.4.x | Only 7.4.4 | 7.4.5 or later |
| FortiClientEMS | 7.2.x | Not affected | - |
| FortiClientEMS | 8.0.x | Not affected | - |
| FortiClientEMS Cloud | All | Not affected | - |
Urgent Action Recommended:
Site header or error-based SQLi patterns).Official Fortinet Advisory:
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142
Site header handling).Note: The flaw was introduced during a middleware refactoring in 7.4.4 related to multi-tenancy support and was silently patched in 7.4.5.
This repository is maintained for defensive security, awareness, and informational purposes only. Always refer to the official Fortinet advisory for the most accurate and up-to-date guidance.
No public exploits are included here.
⭐ Star this repo if it helped you stay secure!
🛠️ Contributions, corrections, or additional IOCs are welcome via Pull Requests.
Last Updated: March 2026