logo

FortiClient Hit by Severe SQL Injection Vulnerability Enabling Database Intrusion

ID: a65bcd7e-e346-5f2e-861f-30647d1645d3

STIX ID: report--a65bcd7e-e346-5f2e-861f-30647d1645d3

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers disclosed CVE-2026-21643, a critical pre-authentication SQL injection in Fortinet FortiClient EMS 7.4.4 when the multi-tenant "Sites" feature is enabled; the flaw (CVSS 9.1) permits unauthenticated attackers to send a single request to /api/v1/init_consts to execute arbitrary SQL, potentially yielding database administrator privileges, OS command execution, and full network takeover. Fortinet fixed the issue in 7.4.5; organizations are advised to upgrade immediately, restrict EMS web access or disable multi-tenant functionality as a temporary mitigation, and review web server logs for unusual 500 errors or long responses on the affected endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.