An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.5 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 |
|
History
Fri, 06 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |
| First Time appeared |
Fortinet
Fortinet forticlientems |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:fortinet:forticlientems:7.4.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlientems |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-02-06T08:25:37.239Z
Reserved: 2026-01-02T08:41:26.514Z
Link: CVE-2026-21643
No data.
Status : Received
Published: 2026-02-06T09:15:49.330
Modified: 2026-02-06T09:15:49.330
Link: CVE-2026-21643
No data.
OpenCVE Enrichment
No data.
Weaknesses