CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Other sources
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiClientEMSto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
Fortinet FortiClientEMSto a version that resolves this vulnerability.Fixed in 8.0.0 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of FortiClientEMS if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21643?
CVE-2026-21643 is categorized as a critical severity vulnerability due to its potential to allow unauthorized code execution.
How do I fix CVE-2026-21643?
To fix CVE-2026-21643, update Fortinet FortiClientEMS to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-21643?
CVE-2026-21643 affects users of Fortinet FortiClientEMS version 7.4.4 and potentially earlier versions.
What does CVE-2026-21643 allow an attacker to do?
CVE-2026-21643 allows an unauthenticated attacker to execute unauthorized commands on the affected system.
What are the symptoms of an exploitation of CVE-2026-21643?
Symptoms of exploitation of CVE-2026-21643 may include unusual application behavior or unauthorized access to sensitive data.