Publicly Disclosed: Bishop Fox Reveals Critical Pre-Auth SQL Injection in FortiClient EMS
ID: 410cdd73-0675-58ed-a39b-6469e3cc284a
STIX ID: report--410cdd73-0675-58ed-a39b-6469e3cc284a
Feed Name: securityonline.info
Bishop Fox published a technical deep-dive on a critical unauthenticated SQL injection in FortiClient EMS (CVE-2026-21643, CVSS 9.1) introduced in 7.4.4 when multi-tenant processing passes the "Site" HTTP header directly into database queries; a single crafted request can yield arbitrary SQL execution and full compromise of the EMS and managed endpoints. The report outlines impact (admin credentials, endpoint inventory, policies, certificates), detection advice (enable full statement logging to catch time-based injections), and mitigations including immediate upgrade to FortiClient EMS 7.4.5, restricting web access, disabling multi-tenancy if unused, and applying WAF rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
