logo

Publicly Disclosed: Bishop Fox Reveals Critical Pre-Auth SQL Injection in FortiClient EMS

ID: 410cdd73-0675-58ed-a39b-6469e3cc284a

STIX ID: report--410cdd73-0675-58ed-a39b-6469e3cc284a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Bishop Fox published a technical deep-dive on a critical unauthenticated SQL injection in FortiClient EMS (CVE-2026-21643, CVSS 9.1) introduced in 7.4.4 when multi-tenant processing passes the "Site" HTTP header directly into database queries; a single crafted request can yield arbitrary SQL execution and full compromise of the EMS and managed endpoints. The report outlines impact (admin credentials, endpoint inventory, policies, certificates), detection advice (enable full statement logging to catch time-based injections), and mitigations including immediate upgrade to FortiClient EMS 7.4.5, restricting web access, disabling multi-tenancy if unused, and applying WAF rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.