Executive brief
FortiClient EMS is a management solution used by organizations to oversee and secure endpoint devices. A critical security flaw allows an unauthenticated attacker to send malicious requests over the network to take control of the management server. This could lead to full system compromise, unauthorized access to sensitive endpoint data, and the ability to execute arbitrary commands on the server.
Technical details
A SQL injection vulnerability (CWE-89) exists in Fortinet FortiClient EMS due to improper neutralization of special elements used in SQL commands. The flaw is reachable via specifically crafted HTTP requests sent to the server. Because the vulnerability does not require authentication or user interaction, a remote attacker can exploit it to achieve unauthorized code execution or command injection on the underlying system. The vulnerability has been observed being exploited in the wild and affects versions 7.4.0 through 7.4.4. Users are advised to upgrade to version 7.4.5 or later.
Affected products
- Fortinet FortiClient EMS 7.4.0 through 7.4.4
Timeline
- 2026-02-06: disclosed: Initial disclosure by Fortinet
- 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-04-13: exploited: Confirmed active exploitation in the wild