/Vulnerability Library

Fortinet FortiClientEMS 7.4.4 - SQL Injection

CVE-2026-21643
Verified

Description

Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The 'Site' HTTP header value is passed directly into the PostgreSQL search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary SQL commands. This can lead to information disclosure, database manipulation, or OS command execution when chained with PostgreSQL functions.

Severity

Critical

CVSS Score

9.8

Exploit Probability

94%

Affected Product

forticlientems

Published Date

April 8, 2026

Template Author

ritikchaddha

CVE-2026-21643.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-21643
CWE ID:
cwe-89

References

https://www.fortiguard.com/psirt/FG-IR-2026-21643https://nvd.nist.gov/vuln/detail/CVE-2026-21643

Remediation Steps

Upgrade FortiClientEMS to a patched version as recommended by Fortinet. As a workaround, restrict network access to the FortiClientEMS management interface and apply WAF rules to filter malicious Site header values.